openspec-ff-change

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local shell commands via the openspec CLI to manage project changes and retrieve artifact instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from CLI output and local artifact files. 1. Ingestion points: Output from openspec status and openspec instructions commands, and local dependency files. 2. Boundary markers: Not present. 3. Capability inventory: Execution of openspec commands and file system writes. 4. Sanitization: Not explicitly performed on ingested data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 04:01 AM
Security Audit — agent-trust-hub — openspec-ff-change