Openspec OnboardSAFE
多模型协作工作流引擎 — /ccg:go 一个命令,AI 自动分析意图、选择策略、编排 Codex + Gemini + Claude 协作执行
Overview
多模型协作工作流引擎 — /ccg:go 一个命令,AI 自动分析意图、选择策略、编排 Codex + Gemini + Claude 协作执行
f1675029baf7OBSERVED · 2026-10-07What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: openspec-onboard description: Guided onboarding for OpenSpec - walk through a complete workflow cycle with narration and real codebase work. license: MIT compatibility: Requires openspec CLI. metadata: author: openspec version: "1.0" generatedBy: "1.1.1" --- Guide the user through their first complete OpenSpec workflow cycle. This is a teaching experience—you'll do real work in their codebase while explaining each step. --- ## Preflight Before starting, check if OpenSpec is initialized: ```bash openspec status --json 2>&1 || echo "NOT_INITIALIZED" ``` **If not initialized:** > OpenSpec isn't set up in this project yet. Run `openspec init` first, then come back to `/opsx:onboard`. Stop here if not initialized. --- ## Phase 1: Welcome Display: ``` ## Welcome to OpenSpec! I'll walk you through a complete change cycle—from idea to implementation—using a real task in your codebase. Along the way, you'll learn the workflow by doing it. **What we'll do:** 1. Pick a small, real task in your codebase 2. Explore the problem briefly 3. Create a change (the container for our work) 4. Build the artifacts: proposal → specs → design → tasks 5. Implement the tasks 6. Archive the completed change **Time:** ~15-20 minutes Let's start by finding something to work on. ``` --- ## Phase 2: Task Selection ### Codebase Analysis Scan the codebase for small improvement opportunities. Look for: 1. **TODO/FIXME comments** - Search for `TODO`, `FIXME`, `HACK`, `XXX` in code files 2. **Missing error handling** - `catch` blocks that swallow errors, risky operations without try-catch 3. **Functions without tests** - Cross-reference `src/` with test directories 4. **Type issues** - `any` types in TypeScript files (`: any`, `as any`) 5. **Debug artifacts** - `console.log`, `console.debug`, `debugger` statements in non-debug code 6. **Missing validation** - User input handlers without validation Also check recent git activity: ```bash git log --oneline -10 2>/dev/null || echo "No git history" ``` ### Present Suggestions From your analysis, present 3-4 specific suggestions: ``` ## Task Suggestions Based on scanning your codebase, here are some good starter tasks: **1. [Most promising task]** Location: `src/path/to/file.ts:42` Scope: ~1-2 files, ~20-30 lines Why it's good: [brief reason] **2. [Second task]** Location: `src/another/file.ts` Scope: ~1 file, ~15 lines Why it's good: [brief reason] **3. [Third task]** Location: [location] Scope: [estimate] Why it's good: [brief reason] **4. Something else?** Tell me what you'd like to work on. Which task interests you? (Pick a number or describe your own) ``` **If nothing found:** Fall back to asking what the user wants to build: > I didn't find obvious quick wins in your codebase. What's something small you've been meaning to add or fix? ### Scope Guardrail If the user picks or describes something too large (major feature, multi-day work): ``` That's a valuable task, but it's probably larger than ideal for your first OpenSpec run-through. For learning the workflow, smaller is better—it lets you see the full cycle without getting stuck in implementation details. **Options:** 1. **Slice it smaller** - What's the smallest useful piece of [their task]? Maybe just [specific slice]? 2. **Pick something else** - One of the other suggestions, or a different small task? 3. **Do it anyway** - If you really want to tackle this, we can. Just know it'll take longer. What would you prefer? ``` Let the user override if they insist—this is a soft guardrail. --- ## Phase 3: Explore Demo Once a task is selected, briefly demonstrate explore mode: ``` Before we create a change, let me quickly show you **explore mode**—it's how you think through problems before committing to a direction. ``` Spend 1-2 minutes investigating the relevant code: - Read the file(s) involved - Draw a quick ASCII diagram if it helps - Note any considerations ``` ## Quick Exploration [Your brief analysis—what you found, any considerations] ┌─────────────────────────────────────────┐ │ [Optional: ASCII diagram if helpful] │ └─────────────────────────────────────────┘ Explore mode (`/opsx:explore`) is for this kind of thinking—investigating before implementing. You can use it anytime you need to think through a problem. Now let's create a change to hold our work. ``` **PAUSE** - Wait for user acknowledgment before proceeding. --- ## Phase 4: Create the Change **EXPLAIN:** ``` ## Creating a Change A "change" in OpenSpec is a container for all the thinking and planning around a piece of work. It lives in `openspec/changes/<name>/` and holds your artifacts—proposal, specs, design, tasks. Let me create one for our task. ``` **DO:** Create the change with a derived kebab-case name: ```bash openspec new change "<derived-name>" ``` **SHOW:** ``` Created: `openspec/changes/<name>/` The folder structure: ``` openspec/changes/<name>/ ├── proposal.md ← Why we're doing this (empty, we'll fill it) ├── design.md ← How we'll build it (empty) ├── specs/ ← Detailed requirements (empty) └── tasks.md ← Implementation checklist (empty) ``` Now let's fill in the first artifact—the proposal. ``` --- ## Phase 5: Proposal **EXPLAIN:** ``` ## The Proposal The proposal captures **why** we're making this change and **what** it involves at a high level. It's the "elevator pitch" for the work. I'll draft one based on our task. ``` **DO:** Draft the proposal content (don't save yet): ``` Here's a draft proposal: --- ## Why [1-2 sentences explaining the problem/opportunity] ## What Changes [Bullet points of what will be different] ## Capabilities ### New Capabilities - `<capability-name>`: [brief description] ### Modified Capabilities <!-- If modifying existing behavior --> ## Impact - `src/path/to/file.ts`: [what changes] - [other files if applicable] --- Does this capture the intent? I can adjust before we
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (0)
No findings outside the package's declared scope.
Gates applied: no_behavioural_pass.
f1675029baf7full audit observations/trust-audit/skill/fengshao1227__openspec-onboard.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | f1675029baf7 | SAFE | B | 89 | first audit |
Questions
What does the Openspec Onboard skill do?
多模型协作工作流引擎 — /ccg:go 一个命令,AI 自动分析意图、选择策略、编排 Codex + Gemini + Claude 协作执行
Is Openspec Onboard safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Openspec Onboard access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
How current is this page?
The grade is for one exact copy of the source (f1675029baf7), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.