launch-sub-agent

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill takes arbitrary user input via $ARGUMENTS and interpolates it directly into a prompt for a sub-agent. This creates a surface where a malicious task description could attempt to override the sub-agent's instructions.
  • Ingestion points: Task description is pulled from $ARGUMENTS in SKILL.md (Phase 4.2).
  • Boundary markers: The skill uses XML-style tags (<task>, <constraints>, <context>, <output>) to delimit the user data, which serves as a mitigation against accidental instruction following.
  • Capability inventory: The skill uses a Task tool to execute the generated prompt across different models (Opus, Sonnet, Haiku).
  • Sanitization: There is no explicit sanitization or escaping of the user input before it is placed within the boundary tags.
  • [COMMAND_EXECUTION]: The skill invokes the Task tool (Phase 5) to dispatch sub-agents. While this is the intended functionality for an orchestrator, it represents the execution of dynamically generated instructions based on user-provided task descriptions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:10 AM
Security Audit — agent-trust-hub — launch-sub-agent