openspec-bulk-archive

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it reads and merges files from openspec/changes/ and openspec/specs/. Instructions embedded in these files by an attacker could potentially influence the agent's behavior during the merging or conflict resolution process.
  • Ingestion points: Local filesystem paths openspec/changes/ and openspec/specs/.
  • Boundary markers: There are no explicit instructions or delimiters provided to ensure the agent ignores embedded commands within the processed files.
  • Capability inventory: The skill involves filesystem write operations, including moving files to openspec/changes/archive/ and merging content into the specs/ directory.
  • Sanitization: The workflow requires the user to review and confirm the resolution plan before final execution, which provides a layer of human oversight.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 04:14 AM
Security Audit — agent-trust-hub — openspec-bulk-archive