subagent-driven-development
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection due to its processing of external implementation plans and generated code. Ingestion points: The implementer subagent reads task descriptions and context from implementation plans. Boundary markers: The provided prompt templates lack explicit delimiters to isolate plan-derived data from instructions. Capability inventory: The subagent has permissions to write files, execute tests, and commit to version control. Sanitization: No specific sanitization logic is applied to the input plan text. Note: This surface is mitigated by the two-stage review process which requires independent code verification.
- [SAFE]: The skill represents a legitimate development methodology. No evidence of malicious command execution, unauthorized data exfiltration, obfuscation, or persistence mechanisms was detected across the instructions and prompt templates.
Audit Metadata