openspec-archive-change

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands such as openspec, codegraph, mkdir, and mv to manage the local lifecycle of project changes. These commands are used for status checking, code discovery, and file organization within the project's own directory structure.
  • [DATA_EXFILTRATION]: No network activity or unauthorized data transmission was detected. File movements are restricted to the local workspace defined by the openspec configuration.
  • [PROMPT_INJECTION]: The skill contains no instructions aimed at overriding agent behavior or bypassing safety filters. It explicitly implements user-review checkpoints via the AskUserQuestion tool for important decisions.
  • [REMOTE_CODE_EXECUTION]: No patterns of downloading or executing remote code from external sources were found. All executable logic relies on pre-installed local CLI tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 03:34 AM
Security Audit — agent-trust-hub — openspec-archive-change