launch-sub-agent
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill takes arbitrary user input via
$ARGUMENTSand interpolates it directly into a prompt for a sub-agent. This creates a surface where a malicious task description could attempt to override the sub-agent's instructions. - Ingestion points: Task description is pulled from
$ARGUMENTSinSKILL.md(Phase 4.2). - Boundary markers: The skill uses XML-style tags (
<task>,<constraints>,<context>,<output>) to delimit the user data, which serves as a mitigation against accidental instruction following. - Capability inventory: The skill uses a
Tasktool to execute the generated prompt across different models (Opus, Sonnet, Haiku). - Sanitization: There is no explicit sanitization or escaping of the user input before it is placed within the boundary tags.
- [COMMAND_EXECUTION]: The skill invokes the
Tasktool (Phase 5) to dispatch sub-agents. While this is the intended functionality for an orchestrator, it represents the execution of dynamically generated instructions based on user-provided task descriptions.
Audit Metadata