subagent-implement
Warn
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands and test "gates" on code branches that have been modified by subagents.
- Evidence: SKILL.md contains instructions to "Run the gate on that branch, whatever the agent said about it."
- [DYNAMIC_EXECUTION]: Verification involves executing code that was dynamically modified by AI subagents at runtime based on external ticket descriptions.
- Evidence: SKILL.md (Step 5) requires the parent agent to run tests/gates on subagent-modified code.
- [PROMPT_INJECTION]: The skill provides instructions to bypass interactive safety confirmations for subagents by using a pre-formatted "authorization line" to trick the agent into proceeding without human verification.
- Evidence: SKILL.md states: "The authorization line: name the skill the human invoked and the date, so the agent does not stall on a confirmation it cannot get."
- [INDIRECT_PROMPT_INJECTION]: The skill has a significant attack surface for indirect prompt injection as it processes untrusted ticket data and executes code derived from it.
- Ingestion points: SKILL.md (Step 1: "Read every ticket in full").
- Boundary markers: Absent for untrusted ticket content.
- Capability inventory: Shell command execution via git, gh, and the "gate" verification process.
- Sanitization: Absent; the verification step itself involves executing the untrusted output without a sandbox.
Audit Metadata