subagent-driven-development

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by interpolating untrusted plan data into subagent prompts.
  • Ingestion points: Task descriptions are extracted from plan files (e.g., docs/plans/feature-plan.md) and used in implementer-prompt.md and spec-reviewer-prompt.md.
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the ingested task text.
  • Capability inventory: The implementer subagent utilizes the general-purpose tool to write files, execute tests, and commit code.
  • Sanitization: No validation or filtering is applied to the task requirements before they are passed to the subagents.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:18 PM
Security Audit — agent-trust-hub — subagent-driven-development