subagent-driven-development
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes a persona ('Kent Beck') and specific instructions to guide the agent's behavior. These are standard instructional techniques designed to improve output quality and do not attempt to bypass core safety constraints or extract system prompts.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process implementation plans and task descriptions provided by the user or generated by other skills. This represents an attack surface for indirect prompt injection; however, the skill mitigates this by instructing the agent to curate specific context for fresh subagents and enforcing multi-stage review gates.
- [EXTERNAL_DOWNLOADS]: The skill mentions integration with other workflow skills prefixed with 'superpowers:' (e.g., 'superpowers:writing-plans'). These are internal skill references within the platform environment and do not involve downloading or executing code from unverified remote sources.
- [COMMAND_EXECUTION]: While the skill describes a process involving git operations (SHAs, commits, worktrees) and running tests, these are standard activities within a software development domain and are initiated within the context of the agent's authorized tools.
Audit Metadata