openspec-archive-change
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill performs directory management using shell commands like
mkdirandmv. The<name>variable, which can be provided by the user, is interpolated directly into these commands. If the variable contains shell metacharacters and is not properly sanitized by the agent platform, it could lead to command injection.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from atasks.mdfile to determine workflow completion. - Ingestion points: Step 3 involves reading the
tasks.mdfile from the filesystem. - Boundary markers: The instructions do not specify any delimiters or safety warnings to ignore instructions embedded within the file content.
- Capability inventory: The skill has capabilities to execute shell commands (
mkdir,mv,openspec) and invoke subagents. - Sanitization: There is no mention of sanitizing or validating the contents of
tasks.mdbefore it is processed by the agent.
Audit Metadata