subagent-driven-development

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed entirely of markdown documentation and Graphviz diagrams. It functions as a process guide for coordinating subagents and does not include scripts, binaries, or automated execution logic.
  • [EXTERNAL_DOWNLOADS]: The attribution file identifies the source repository as obra/superpowers on GitHub and provides a standard installation command. This reference is used for distribution and metadata and does not trigger unverified runtime downloads.
  • [PROMPT_INJECTION]: The instructions provide operational boundaries and quality control steps (e.g., mandatory reviews, question-answering phases). There are no instructions that attempt to bypass AI safety filters or exfiltrate system prompts.
  • [DATA_EXFILTRATION]: No network operations, credential access, or sensitive file system interactions are defined. The example paths mentioned (e.g., ~/.config/superpowers/hooks/) are illustrative of standard configuration management.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 09:36 AM
Security Audit — agent-trust-hub — subagent-driven-development