openspec-explore
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill uses a restrictive configuration via
allowed-tools, limiting command execution to theopenspecCLI namespace. This enforces the principle of least privilege. - [COMMAND_EXECUTION]: The skill leverages local
openspeccommands (e.g.,list,status,store) to provide context about the development project. These operations are diagnostic in nature and do not perform network requests or unauthorized file modifications. - [SAFE]: Behavioral guardrails are clearly defined, instructing the agent to 'NEVER write code or implement features' while in explore mode, which mitigates the risk of accidental or malicious code changes.
- [SAFE]: No indicators of prompt injection, credential harvesting, or data exfiltration were found. The skill operates locally on OpenSpec repositories.
Audit Metadata