openspec-continue-change

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill interacts with the local system by executing the openspec CLI tool. It dynamically inserts variables such as <name> and <artifact-id> into shell commands (e.g., openspec status --change "<name>"). This pattern requires the agent's execution environment to properly sanitize or quote arguments to prevent command injection.
  • [EXTERNAL_DOWNLOADS]: The skill documentation specifies a dependency on the openspec CLI. It does not contain scripts to automatically download or install this tool from the internet, but functionality is contingent on its presence in the system PATH.
  • [SAFE]: No evidence of data exfiltration, network requests to external domains, or hardcoded credentials was found.
  • [SAFE]: The instructions do not contain obfuscated code, hidden characters, or prompt injection patterns designed to bypass AI safety guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 11:34 AM
Security Audit — agent-trust-hub — openspec-continue-change