openspec-explore
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes 'openspec' and 'codegraph' CLI tools to gather project context and explore codebase relationships. These commands are integral to the skill's intended discovery functions.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data including user-defined topics and codebase content. 1. Ingestion points: User topics and codebase artifacts processed via CLI tools. 2. Boundary markers: No explicit delimiters or ignore-instructions are used for external data. 3. Capability inventory: Reading local files and executing specified CLI tools; writing application code is explicitly forbidden. 4. Sanitization: CLI tool arguments are interpolated from user input without documented sanitization logic.
Audit Metadata