openspec-verify-change
Warn
Audited by Snyk on Jul 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). The skill runs
openspec instructions apply --change "<name>" --jsonand then “read all available artifacts fromcontextFiles”; those artifacts (e.g.,tasks.md, delta specs,design.md) are outsider-authored change artifacts from theopenspec/changes/<name>/...directory, which the operating user did not author/choose at runtime, so their readable text can be injected into the agent’s LLM context.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata