change-disposition
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands to perform repository maintenance and verification tasks.
- Evidence: Use of a pipeline involving
find,sort,xargs, andsha256sumto generate byte-level fingerprints of the specification tree for integrity checks. - Evidence: Use of
ripgrep(rg) with fixed-string matching to search for change identifiers within proposal files. - Evidence: Invocation of a project-specific
openspeccommand-line tool for archiving change directories. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by ingesting data from project artifacts.
- Ingestion points: Reads content from
proposal.mdfiles and authoritative task artifacts within theopenspec/changesdirectory to verify dependencies and task completion. - Boundary markers: The skill does not define specific delimiters for separating ingested file content from its own instructions, although it uses strict template formats for output.
- Capability inventory: The skill has permissions to search the file system, compute file hashes, write new markdown files, and execute the
openspecarchival command. - Sanitization: The instructions mandate the normalization of informal requests (e.g., "abandoned" or "wontfix") into canonical dispositions, which serves as a validation step for ingested data.
Audit Metadata