openspec-explore

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the openspec command-line interface to list and retrieve project metadata (openspec list --json). This is a legitimate use of a vendor tool to establish context within the development environment.
  • [PROMPT_INJECTION]: The skill includes instructions to the agent to adopt a collaborative 'thinking' posture. It specifically sets boundaries by instructing the agent to 'NUNCA' (never) write code or implement features while in this mode, which serves as a safety guardrail.
  • [DATA_EXFILTRATION]: While the skill reads local project files for architectural mapping and investigation, it contains no instructions for network operations or external data transfer.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 07:50 PM