openspec-new-change

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the openspec CLI to execute shell commands such as openspec new change and openspec status.
  • [COMMAND_EXECUTION]: Potential indirect prompt injection surface exists as user input is interpolated into shell command arguments. Ingestion point: User-provided name or description in SKILL.md. Boundary markers: None. Capability inventory: Shell command execution via openspec CLI. Sanitization: The skill contains specific instructions to validate that names are in kebab-case and to prompt the user if they are invalid, mitigating potential command injection.
  • [SAFE]: No malicious patterns, hardcoded credentials, or unauthorized network requests were detected in the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 04:10 PM
Security Audit — agent-trust-hub — openspec-new-change