openspec-propose
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local
openspecCLI commands to manage change scaffolds and artifact state. Commands includeopenspec new change,openspec status, andopenspec instructions. - [PROMPT_INJECTION]: The skill ingests instructions and project context via the
openspec instructionstool output. It includes explicit guardrails to prevent these internal constraints from being reflected in user-facing output files, which acts as a mitigation against indirect injection and data leakage. - [EXTERNAL_DOWNLOADS]: The skill identifies a dependency on the
openspecCLI but does not attempt to download or install external resources at runtime.
Audit Metadata