openspec-apply-change

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the openspec CLI to manage the task lifecycle, executing commands such as openspec list, openspec status, and openspec instructions. These operations are used to synchronize the agent's state with the local development environment.
  • [DATA_EXPOSURE]: The agent reads various local project artifacts (specifications, designs, and task lists) determined dynamically by the CLI output. This access is scoped to the context files required for task implementation.
  • [INDIRECT_PROMPT_INJECTION]: As the skill interprets instructions and tasks from local files, it possesses an attack surface for indirect prompt injection. The skill mitigates this risk through guardrails that instruct the agent to pause for clarification if tasks are unclear or if implementation reveals design conflicts.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:36 AM
Security Audit — agent-trust-hub — openspec-apply-change