subagent-driven-development
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructs the agent to "Do not pause to check in with your human partner between tasks" and characterizes confirmation prompts like "Should I continue?" as a waste of time. This behavior override encourages autonomous execution and suppresses standard interaction patterns, reducing the user's ability to intervene during the execution of a plan.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of implementation plans. Task descriptions from these plans are extracted and placed directly into the implementer subagent's prompt without security boundaries or sanitization.
- Ingestion points: Task descriptions extracted from repository plan files (referenced in SKILL.md and implementer-prompt.md).
- Boundary markers: The implementer-prompt.md template does not use delimiters or instructions to ignore embedded commands when including external task text.
- Capability inventory: Subagents are given broad permissions to modify files, write tests, and commit changes to the codebase.
- Sanitization: No validation or filtering is applied to the implementation plan content before it is processed by the subagents.
Audit Metadata