accelint-archive-synthesis

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements a 'lint' operation for archived design decisions, which is a legitimate maintenance task within the OpenSpec ecosystem. It manages its own log file (SYNTHESIS-LOG.md) to track progress and suppress previously dismissed findings.
  • [COMMAND_EXECUTION]: The skill performs targeted file system operations, including reading and updating local index files (INDEX.md) within the project's openspec directory. These operations are gated by explicit human confirmation and are limited to status updates or specific row patches.
  • [PROMPT_INJECTION]: The skill identifies a potential indirect prompt injection surface. * Ingestion points: openspec/changes/archive//design.md and openspec/specs//spec.md. * Boundary markers: Absent. * Capability inventory: Modifies archive/INDEX.md and specs/INDEX.md; invokes writer skills via the findings: interface. * Sanitization: Absent; the skill relies on sub-agent parsing and mandatory human confirmation (Step 7) to mitigate risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 08:13 PM
Security Audit — agent-trust-hub — accelint-archive-synthesis