openspec-bulk-archive
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it reads and merges files from
openspec/changes/andopenspec/specs/. Instructions embedded in these files by an attacker could potentially influence the agent's behavior during the merging or conflict resolution process. - Ingestion points: Local filesystem paths
openspec/changes/andopenspec/specs/. - Boundary markers: There are no explicit instructions or delimiters provided to ensure the agent ignores embedded commands within the processed files.
- Capability inventory: The skill involves filesystem write operations, including moving files to
openspec/changes/archive/and merging content into thespecs/directory. - Sanitization: The workflow requires the user to review and confirm the resolution plan before final execution, which provides a layer of human oversight.
Audit Metadata