openspec-archive-change

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: Employs standard shell utilities like mkdir and mv alongside the openspec CLI to manage project archives. These operations are limited to the project's directory structure.
  • [SAFE]: Includes explicit guardrails requiring user selection of changes and confirmation via the AskUserQuestion tool when warnings about incomplete tasks or artifacts are present.
  • [SAFE]: Analyzes local project files (tasks.md, delta specs) for status reporting without executing their content, mitigating indirect injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 03:17 PM