delegated-development

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for injecting task descriptions from project plans into subagent prompts.
  • Ingestion points: Pastes full task text and requirements into prompts for implementer and reviewer subagents.
  • Boundary markers: Uses logical headers to organize subagent prompts and explicitly instructs reviewers to verify code independently.
  • Capability inventory: Subagents are granted broad permissions to modify the codebase, run tests, and commit changes.
  • Sanitization: The architecture relies on multi-layered verification (self-review plus two external reviews) to identify and correct any malicious or incorrect instructions introduced via the task input.
  • [SAFE]: No indicators of malicious intent, obfuscation, or unauthorized data access were found. The skill is designed with defensive patterns for agent orchestration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:00 PM
Security Audit — agent-trust-hub — delegated-development