openspec-continue-change
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill interacts with the local system by executing the
openspecCLI tool. It dynamically inserts variables such as<name>and<artifact-id>into shell commands (e.g.,openspec status --change "<name>"). This pattern requires the agent's execution environment to properly sanitize or quote arguments to prevent command injection. - [EXTERNAL_DOWNLOADS]: The skill documentation specifies a dependency on the
openspecCLI. It does not contain scripts to automatically download or install this tool from the internet, but functionality is contingent on its presence in the system PATH. - [SAFE]: No evidence of data exfiltration, network requests to external domains, or hardcoded credentials was found.
- [SAFE]: The instructions do not contain obfuscated code, hidden characters, or prompt injection patterns designed to bypass AI safety guardrails.
Audit Metadata