openspec-onboard
Pass
Audited by Gen Agent Trust Hub on Mar 5, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
openspeccommand-line interface to manage the lifecycle of code changes, including status checks, creating new change containers, and archiving results locally.\n- [COMMAND_EXECUTION]: Utilizesgit logto examine recent repository history, helping the agent provide relevant task suggestions to the user.\n- [DATA_EXPOSURE]: Performs local scanning of project source files to identifyTODOorFIXMEcomments and analyze code patterns (such as missing error handling oranytypes in TypeScript). This information is used solely to interact with the user and does not involve external transmission.
Audit Metadata