openspec-apply-change
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill reads instructions from local project files (proposals, specs, designs, and tasks) to drive implementation actions, creating an attack surface for instructions embedded in data.\n- Ingestion points: Project artifacts identified via the
contextFilesoutput of theopenspecCLI (SKILL.md, step 4).\n- Boundary markers: None; the agent is instructed to read these files directly to gather implementation context without delimiters or warnings.\n- Capability inventory: Authorized to execute specificopenspecCLI commands and possesses general file modification capabilities.\n- Sanitization: No validation, escaping, or filtering of the content from external files is specified in the workflow.
Audit Metadata