implement-unattended-no-subagents

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard development tools such as git fetch, git worktree, and gh pr list to manage the codebase and pull requests.
  • [COMMAND_EXECUTION]: Uses grep to scan the local repository for 'TEMPORARY AGENT' markers to audit inherited or existing autonomous decisions.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest ticket URLs and specifications. This represents a potential surface for indirect prompt injection if an attacker-controlled ticket contains malicious instructions. However, the risk is mitigated by the disable-model-invocation: true flag, which prevents the agent from delegating tasks to sub-agents, and the human-centric invocation requirements.
  • [SAFE]: The skill documentation includes explicit safety guidance, warning the agent to stop if it is invoked by another skill rather than a human, preventing automated chains from 'manufacturing' human approval.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 12:37 PM
Security Audit — agent-trust-hub — implement-unattended-no-subagents