openspec-explore

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it reads untrusted content from the local codebase and openspec configuration files to ground its reasoning and planning process. While the skill is restricted from writing application code and limited to the openspec CLI, malicious instructions embedded in project files could potentially influence the agent's behavior or the content of generated OpenSpec artifacts.\n
  • Ingestion points: Local codebase files and the openspec/config.yaml file (referenced in SKILL.md).\n
  • Boundary markers: Absent; the skill lacks explicit delimiters or instructions to distinguish between its core logic and external data provided by the file system.\n
  • Capability inventory: Execution of openspec CLI commands via Bash (SKILL.md) and file system operations restricted to OpenSpec artifact paths.\n
  • Sanitization: Absent; external file content is processed directly into the agent's thinking context without filtering or validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 01:54 PM
Security Audit — agent-trust-hub — openspec-explore