openspec-config

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains purely documentation and instructional content for the OpenSpec CLI tool. No obfuscation, data exfiltration, or malicious persistence mechanisms were found.
  • [COMMAND_EXECUTION]: The skill instructs the agent on how to use openspec config subcommands (list, get, set, unset, reset, edit, path) to manage user-level settings. This is consistent with the skill's primary purpose.
  • [EXTERNAL_DOWNLOADS]: References official documentation links on GitHub for the OpenSpec project (github.com/Fission-AI/OpenSpec). These are legitimate resources for the tool described.
  • [PROMPT_INJECTION]: The documentation describes an indirect prompt injection surface where the context and rules fields from the openspec/config.yaml file are injected into all artifact instructions.
  • Ingestion points: openspec/config.yaml (context and rules fields).
  • Boundary markers: The skill notes that content is wrapped in <project-context> and <project-rules> tags.
  • Capability inventory: The tool allows modifying project configuration which subsequently affects AI artifact generation instructions.
  • Sanitization: No explicit sanitization or validation of the injected content is described in the skill documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:11 PM
Security Audit — agent-trust-hub — openspec-config