openspec-ff-change
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Executes the openspec CLI to initialize changes, check status, and retrieve artifact instructions. The skill includes a mitigation step requiring the agent to derive a sanitized kebab-case name from user input before execution.
- [PROMPT_INJECTION]: Ingests artifact-specific instructions and rules from the openspec CLI's JSON output. This data guides the agent's file generation process, creating a surface for indirect prompt injection if the tool's data source were to contain malicious instructions.
Audit Metadata