subagent-driven-development

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external implementation plans (e.g., feature-plan.md) and interpolates task descriptions into sub-agent prompts. Sub-agents are granted significant capabilities including file system modification, command execution (for testing), and version control operations. While the methodology recommends two-stage reviews, the lack of explicit input sanitization or boundary markers (like XML delimiters) for external plan data creates a surface for indirect prompt injection if a plan file contains malicious instructions for the sub-agents.
  • Ingestion points: Plan files read by the controller agent (e.g., docs/opencode-skills/plans/feature-plan.md).
  • Boundary markers: The skill instructions recommend providing "precisely crafted" context but do not specify technical delimiters or "ignore embedded instructions" warnings for the ingested data.
  • Capability inventory: Sub-agents have permissions to implement code, run tests, and commit changes to the repository (referenced in SKILL.md process description).
  • Sanitization: No explicit sanitization or validation of the plan file content is performed before it is passed to the implementation or review sub-agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — subagent-driven-development