openspec-sync-specs
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill uses legitimate local CLI tools (openspec and codegraph) to perform its stated function of synchronizing specification files.
- [COMMAND_EXECUTION]: Executes local commands openspec list, openspec status, and codegraph explore. These operations are consistent with the skill's description and are gated by user selection or context resolution.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from delta spec files and uses it to update main specifications. While this involves processing external markdown content, the instructions provide a structured approach for merging data, reducing the likelihood of the agent misinterpreting content as instructions.
Audit Metadata