openspec-apply-change

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill reads instructions from local project files (proposals, specs, designs, and tasks) to drive implementation actions, creating an attack surface for instructions embedded in data.\n- Ingestion points: Project artifacts identified via the contextFiles output of the openspec CLI (SKILL.md, step 4).\n- Boundary markers: None; the agent is instructed to read these files directly to gather implementation context without delimiters or warnings.\n- Capability inventory: Authorized to execute specific openspec CLI commands and possesses general file modification capabilities.\n- Sanitization: No validation, escaping, or filtering of the content from external files is specified in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 09:55 AM
Security Audit — agent-trust-hub — openspec-apply-change