subagent-driven-development

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a procedural guide for development orchestration and does not include any executable scripts or binary files.
  • [SAFE]: The process emphasizes isolation and verification, utilizing dedicated sub-agents for specific tasks to minimize context pollution and improve accountability.
  • [SAFE]: The multi-stage review process (spec review and code review) defined in the prompt templates provides a structural defense against accidental or malicious instructions in the input data.
  • [SAFE]: The implementation of sub-agent isolation acts as a security boundary, ensuring that each task is performed within a clean environment.
  • [SAFE]: No patterns associated with data exfiltration, credential theft, or malicious persistence were observed.
  • [SAFE]: The skill processes implementation plans (Ingestion: SKILL.md) passed to sub-agents without explicit boundary markers (Boundary markers: absent); while these agents have file system and test execution capabilities (Capability inventory: superpowers:test-driven-development in SKILL.md), the risk is addressed by the mandatory multi-agent review workflow (Sanitization: absent, mitigated by review).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 06:31 PM
Security Audit — agent-trust-hub — subagent-driven-development