openspec-apply-change
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect instructions by ingesting content from both CLI tool outputs and arbitrary files within the local project repository.\n- Ingestion points: The agent is instructed to read JSON output from
openspec statusandopenspec instructions apply, along with any files identified in thecontextFilesarray, such as specifications or design documents.\n- Boundary markers: The skill includes logic to maintain the integrity of the workflow by requiring the agent to report conflicts between external 'context' and primary instructions, and it explicitly forbids external data from overriding task completion or blocked states.\n- Capability inventory: The skill utilizes theopenspecCLI through a restricted Bash namespace and performs file modifications to implement code changes and mark tasks as completed.\n- Sanitization: No technical filtering or sanitization is performed on the ingested content; instead, the skill provides behavioral instructions to handle conflicting project facts and advisory guidance.
Audit Metadata