openspec-propose
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local
openspecCLI commands (new change,status,instructions) to orchestrate project changes. These operations are consistent with the skill's stated purpose and use the developer's own toolset. - [DATA_EXFILTRATION]: File operations are localized to the project's
openspec/changes/directory. The skill does not access sensitive system files (e.g., SSH keys, AWS credentials) or perform unauthorized network transfers. - [PROMPT_INJECTION]: Instructions such as "IMPORTANT" and "Guardrails" are used to define the agent's operational logic and output formatting. No attempts to override safety protocols or extract system prompts were detected.
Audit Metadata