openspec-explore
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
openspecCLI to list project context and manage design artifacts. This is an intended function for coordinating with the OpenSpec workflow.\n- [PROMPT_INJECTION]: The skill processes external data from the codebase and design documents which creates a surface for indirect prompt injection.\n - Ingestion points: Reads source code and markdown files from the local environment, specifically within
openspec/changes/andspecs/.\n - Boundary markers: No delimiters or instructions are provided to the agent to treat this content as untrusted.\n
- Capability inventory: The skill can read local files, write markdown files to the design directories, and execute the
openspecCLI tool.\n - Sanitization: No sanitization or validation is performed on the content read from the files before it is processed by the AI.
Audit Metadata