openspec-propose
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to execute theopenspecCLI for various operations including change creation, status tracking, and instruction retrieval. These operations are restricted to theopenspeccommand scope as defined in the skill's allowed tools list. - [INDIRECT_PROMPT_INJECTION]: The skill processes external content from user-provided descriptions and JSON output from the
openspecCLI, which introduces a potential surface for indirect injection. - Ingestion points: User-supplied build descriptions in Step 1 and JSON instruction sets from the CLI in Step 5.
- Boundary markers: The skill includes a 'Planning boundary' section that explicitly restricts the agent's actions to documentation and planning, prohibiting implementation or code modification.
- Capability inventory: The skill is limited to executing the
openspecCLI and writing markdown files to local paths. - Sanitization: The skill instructs the agent to normalize user input into kebab-case names, which acts as a rudimentary form of input validation.
Audit Metadata