subagent-driven-development

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, hardcoded credentials, or unauthorized access attempts were identified. The skill follows security best practices by using isolated subagent contexts and strictly defining escalation paths for blocked or complex tasks.- [PROMPT_INJECTION]: The skill demonstrates an indirect prompt injection surface as it ingests and processes external implementation plans. This is a functional requirement of the task-execution workflow.
  • Ingestion points: Full task descriptions from implementation plans are pasted into implementer and reviewer subagent prompts.
  • Boundary markers: Absent in the provided templates; task text is not explicitly delimited from agent instructions.
  • Capability inventory: Subagents possess capabilities for file manipulation, testing, and git operations.
  • Sanitization: The risk is mitigated by a multi-agent review process where a separate reviewer agent is instructed to independently verify the implementation against the original requirements without trusting the implementer's report.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 02:30 PM
Security Audit — agent-trust-hub — subagent-driven-development