opsx-propose

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the openspec and codegraph CLI tools to manage the software development lifecycle. It includes commands for creating new changes, querying project status, and exploring codebases using search terms.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided change names and descriptions, which constitutes a potential attack surface for indirect prompt injection.
  • Ingestion points: User input provided as arguments to the /opsx:propose command (SKILL.md).
  • Boundary markers: Absent.
  • Capability inventory: Execution of CLI tools (openspec, codegraph) for project management and document generation (SKILL.md).
  • Sanitization: None specified for the user-provided kebab-case name or description.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 05:53 PM
Security Audit — agent-trust-hub — opsx-propose