subagent-driven-development

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a set of instructions for a development workflow. It does not include any scripts, executable code, or tools capable of performing network operations or accessing sensitive files.
  • [PROMPT_INJECTION]: While the skill processes external tasks and plans (a potential surface for indirect prompt injection), it implements robust mitigation strategies such as mandatory implementation gates, explicit user approval requirements, and a structured two-stage review process for compliance and quality.
  • [SAFE]: The skill references a public repository on a well-known service (github.com/obra/superpowers) as a workflow reference, which is a standard development practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 12:11 PM
Security Audit — agent-trust-hub — subagent-driven-development