Back to skill

Security audit

OpenSpec

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for OpenSpec workflows, but it asks users to install a mutable global npm CLI and can direct broad workspace changes without strong scoping guidance.

Install only if you intend to use OpenSpec for this project. Prefer a pinned, project-local OpenSpec dependency instead of the documented global `@latest` install, review generated `openspec/` and `.claude/` files before committing, and require confirmation before archive or other mutating workflow steps.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Mutable Global npm Dependency Creates a Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation
``` 2. Prefer a project-local development dependency over global installation. Invoke it through an npm script or a locally resolved executable so its scope is limited to the project. 3. Commit `package.json` and `package-lock.json`, then use deterministic installation in automation: ```bash npm ci ``` 4. Review the selected package version, its lifecycle scripts, and its transitive dependency graph before recommending installation. 5. Verify package provenance and registry metadata. Where operationally supported, enforce registry allowlists, package integrity checks, and npm provenance verification. 6. Consider initially installing with lifecycle scripts disabled: ```bash npm install --ignore-scripts --save-dev --save-exact @fission-ai/openspec@ ``` Enable only specifically required scripts after review. 7. Perform installation in a minimally privileged development environment or sandbox. Do not run the installation as root or with `sudo`. 8. Establish an explicit dependency-update process so version changes are reviewed and tested rather than silently inherited through the mutable `latest` tag. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger description is broad enough to activate on many ordinary development requests such as building features, refactors, or planning work, which can cause the skill to engage outside narrowly intended OpenSpec scenarios. In an agent setting, over-broad activation increases the chance of unnecessary tool usage and unintended project state changes, especially because the skill encourages creating and modifying project artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The agent workflow instructs the model to create change folders, write artifact files, validate, and archive changes, but it does not warn that these actions modify the workspace or require user confirmation before destructive or stateful operations. In practice, this can lead an agent to make unsolicited file-system changes, including merging specs and archiving work, which may overwrite intended process controls or alter repository state unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.