subagent-driven-development
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external implementation plans (e.g.,
feature-plan.md) and interpolates task descriptions into sub-agent prompts. Sub-agents are granted significant capabilities including file system modification, command execution (for testing), and version control operations. While the methodology recommends two-stage reviews, the lack of explicit input sanitization or boundary markers (like XML delimiters) for external plan data creates a surface for indirect prompt injection if a plan file contains malicious instructions for the sub-agents. - Ingestion points: Plan files read by the controller agent (e.g.,
docs/opencode-skills/plans/feature-plan.md). - Boundary markers: The skill instructions recommend providing "precisely crafted" context but do not specify technical delimiters or "ignore embedded instructions" warnings for the ingested data.
- Capability inventory: Sub-agents have permissions to implement code, run tests, and commit changes to the repository (referenced in
SKILL.mdprocess description). - Sanitization: No explicit sanitization or validation of the plan file content is performed before it is passed to the implementation or review sub-agents.
Audit Metadata