openspec-explore
Pass
Audited by Gen Agent Trust Hub on Apr 22, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
openspeccommand-line interface to list and retrieve project metadata (openspec list --json). This is a legitimate use of a vendor tool to establish context within the development environment. - [PROMPT_INJECTION]: The skill includes instructions to the agent to adopt a collaborative 'thinking' posture. It specifically sets boundaries by instructing the agent to 'NUNCA' (never) write code or implement features while in this mode, which serves as a safety guardrail.
- [DATA_EXFILTRATION]: While the skill reads local project files for architectural mapping and investigation, it contains no instructions for network operations or external data transfer.
Audit Metadata