openspec-archive-change

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch 'context' and 'operationGuidance' from the output of the 'openspec instructions archive' command and explicitly directs the agent to 'read and consider' this data when performing the archive. This architecture allows external repository configuration to inject instructions into the agent's reasoning process.
  • Ingestion points: The 'context' and 'operationGuidance' fields from the 'openspec instructions archive' JSON output (referenced in SKILL.md).
  • Boundary markers: No explicit delimiters or boundary warnings are present to isolate the external instructions from the agent's core logic.
  • Capability inventory: The agent has permissions to execute 'openspec' commands, perform shell operations (mkdir, mv), and modify specification files (spec.md).
  • Sanitization: While the skill includes logic to prioritize 'controlling inputs' over advisory guidance, the system ultimately relies on the LLM's judgment to resolve conflicts.
  • [COMMAND_EXECUTION]: The skill constructs shell commands such as 'mkdir -p' and 'mv' using variables (like 'changeRoot' and 'planningHome.changesDir') provided by the 'openspec status' JSON output. Although these variables are wrapped in double quotes, the dynamic assembly of shell commands from external tool outputs represents a command execution risk surface.
  • [DYNAMIC_EXECUTION]: The skill generates and performs file system movements and triggers an inline 'openspec-sync-specs' workflow at runtime, which dynamically processes and merges specification content based on the current state of the repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 01:54 PM
Security Audit — agent-trust-hub — openspec-archive-change