openspec-explore

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the openspec CLI to list project context and manage design artifacts. This is an intended function for coordinating with the OpenSpec workflow.\n- [PROMPT_INJECTION]: The skill processes external data from the codebase and design documents which creates a surface for indirect prompt injection.\n
  • Ingestion points: Reads source code and markdown files from the local environment, specifically within openspec/changes/ and specs/.\n
  • Boundary markers: No delimiters or instructions are provided to the agent to treat this content as untrusted.\n
  • Capability inventory: The skill can read local files, write markdown files to the design directories, and execute the openspec CLI tool.\n
  • Sanitization: No sanitization or validation is performed on the content read from the files before it is processed by the AI.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 12:03 PM
Security Audit — agent-trust-hub — openspec-explore