openspec-archive-change

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill performs directory management using shell commands like mkdir and mv. The <name> variable, which can be provided by the user, is interpolated directly into these commands. If the variable contains shell metacharacters and is not properly sanitized by the agent platform, it could lead to command injection.- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from a tasks.md file to determine workflow completion.
  • Ingestion points: Step 3 involves reading the tasks.md file from the filesystem.
  • Boundary markers: The instructions do not specify any delimiters or safety warnings to ignore instructions embedded within the file content.
  • Capability inventory: The skill has capabilities to execute shell commands (mkdir, mv, openspec) and invoke subagents.
  • Sanitization: There is no mention of sanitizing or validating the contents of tasks.md before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 06:33 AM