openspec-continue-change

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes the openspec CLI with various subcommands (list, status, instructions) to retrieve project state and metadata. These commands are used to facilitate the intended workflow and do not include dangerous or arbitrary execution patterns.
  • [DATA_EXPOSURE]: The skill reads existing artifact files (such as proposal.md or capability specs) to provide context for generating new files. This access is restricted to project-specific documentation and does not target sensitive system paths or credentials.
  • [REMOTE_CODE_EXECUTION]: The skill relies on a local openspec CLI environment. It does not attempt to download or execute external scripts from remote servers.
  • [PROMPT_INJECTION]: The instructions include clear guardrails for the agent, such as requiring user confirmation for selection and prohibiting the inclusion of system constraints inside output files. No malicious bypass or override patterns were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 11:12 AM
Security Audit — agent-trust-hub — openspec-continue-change