openspec-apply

Pass

Audited by Gen Agent Trust Hub on Mar 4, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface. Ingestion points: changes/<id>/proposal.md, design.md, and tasks.md. Boundary markers: Absent. Capability inventory: Bash, Write, Edit, and Task. Sanitization: Absent.
  • [COMMAND_EXECUTION]: The skill uses Bash to perform tasks defined in external files, which can be exploited to run arbitrary commands if the input files are malicious.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 4, 2026, 10:18 AM