change-disposition

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands to perform repository maintenance and verification tasks.
  • Evidence: Use of a pipeline involving find, sort, xargs, and sha256sum to generate byte-level fingerprints of the specification tree for integrity checks.
  • Evidence: Use of ripgrep (rg) with fixed-string matching to search for change identifiers within proposal files.
  • Evidence: Invocation of a project-specific openspec command-line tool for archiving change directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by ingesting data from project artifacts.
  • Ingestion points: Reads content from proposal.md files and authoritative task artifacts within the openspec/changes directory to verify dependencies and task completion.
  • Boundary markers: The skill does not define specific delimiters for separating ingested file content from its own instructions, although it uses strict template formats for output.
  • Capability inventory: The skill has permissions to search the file system, compute file hashes, write new markdown files, and execute the openspec archival command.
  • Sanitization: The instructions mandate the normalization of informal requests (e.g., "abandoned" or "wontfix") into canonical dispositions, which serves as a validation step for ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 06:18 PM
Security Audit — agent-trust-hub — change-disposition