openspec-ff-change

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes the openspec CLI to initialize changes, check status, and retrieve artifact instructions. The skill includes a mitigation step requiring the agent to derive a sanitized kebab-case name from user input before execution.
  • [PROMPT_INJECTION]: Ingests artifact-specific instructions and rules from the openspec CLI's JSON output. This data guides the agent's file generation process, creating a surface for indirect prompt injection if the tool's data source were to contain malicious instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 07:34 AM
Security Audit — agent-trust-hub — openspec-ff-change