subagent-driven-development
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill architecture relies on reading implementation plans from external files and passing the raw requirements directly into the instructions for implementation and review subagents.
- Ingestion points: Content is extracted from implementation plan files (e.g.,
docs/plans/feature-plan.md) and injected into the prompt templates located inimplementer-prompt.mdandspec-reviewer-prompt.md. - Boundary markers: The templates interpolate the
[FULL TEXT of task]directly into the instructions. There are no clear delimiters (such as XML tags or dedicated boundary strings) or explicit "ignore embedded instructions" warnings to help the subagent distinguish between the controller's instructions and the potentially untrusted data from the plan. - Capability inventory: Implementation subagents are granted the ability to write code, execute test suites, and commit changes to the repository, which provides a significant capability surface if a plan file contains malicious instructions.
- Sanitization: The skill lacks any automated sanitization, filtering, or validation steps to ensure that the content extracted from the plan files does not attempt to override the subagent's operational guidelines.
Audit Metadata