openspec-new-change
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
openspecCLI to execute shell commands such asopenspec new changeandopenspec status. - [COMMAND_EXECUTION]: Potential indirect prompt injection surface exists as user input is interpolated into shell command arguments. Ingestion point: User-provided name or description in
SKILL.md. Boundary markers: None. Capability inventory: Shell command execution viaopenspecCLI. Sanitization: The skill contains specific instructions to validate that names are in kebab-case and to prompt the user if they are invalid, mitigating potential command injection. - [SAFE]: No malicious patterns, hardcoded credentials, or unauthorized network requests were detected in the skill.
Audit Metadata