openspec-apply-change

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect instructions by ingesting content from both CLI tool outputs and arbitrary files within the local project repository.\n- Ingestion points: The agent is instructed to read JSON output from openspec status and openspec instructions apply, along with any files identified in the contextFiles array, such as specifications or design documents.\n- Boundary markers: The skill includes logic to maintain the integrity of the workflow by requiring the agent to report conflicts between external 'context' and primary instructions, and it explicitly forbids external data from overriding task completion or blocked states.\n- Capability inventory: The skill utilizes the openspec CLI through a restricted Bash namespace and performs file modifications to implement code changes and mark tasks as completed.\n- Sanitization: No technical filtering or sanitization is performed on the ingested content; instead, the skill provides behavioral instructions to handle conflicting project facts and advisory guidance.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 01:54 PM
Security Audit — agent-trust-hub — openspec-apply-change