subagent-driven-development
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by interpolating untrusted plan data into subagent prompts.
- Ingestion points: Task descriptions are extracted from plan files (e.g., docs/plans/feature-plan.md) and used in implementer-prompt.md and spec-reviewer-prompt.md.
- Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the ingested task text.
- Capability inventory: The implementer subagent utilizes the general-purpose tool to write files, execute tests, and commit code.
- Sanitization: No validation or filtering is applied to the task requirements before they are passed to the subagents.
Audit Metadata