openspec-apply
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill describes a workflow that ingests data from local files (tasks.md, design.md) to perform operations like writing code and running tests. This presents a potential surface for indirect prompt injection if those input files contain instructions intended to deviate the agent from its intended behavior.\n
- Ingestion points: Local project artifacts including tasks.md, design.md, and the specs/ directory.\n
- Boundary markers: The instructions do not define specific delimiters for separating task data from system instructions.\n
- Capability inventory: The workflow includes writing and modifying code files and executing test commands.\n
- Sanitization: No validation or sanitization logic is specified for the task content processed by the agent.\n- [EXTERNAL_DOWNLOADS]: The skill contains reference links to documentation on GitHub.\n
- Evidence: Links to github.com/Fission-AI/OpenSpec for command and concept documentation. These are standard documentation references to a well-known service.
Audit Metadata