opsx-propose
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the
openspecandcodegraphCLI tools to manage the software development lifecycle. It includes commands for creating new changes, querying project status, and exploring codebases using search terms. - [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided change names and descriptions, which constitutes a potential attack surface for indirect prompt injection.
- Ingestion points: User input provided as arguments to the
/opsx:proposecommand (SKILL.md). - Boundary markers: Absent.
- Capability inventory: Execution of CLI tools (
openspec,codegraph) for project management and document generation (SKILL.md). - Sanitization: None specified for the user-provided kebab-case name or description.
Audit Metadata