delegated-development
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a process for injecting task descriptions from project plans into subagent prompts.
- Ingestion points: Pastes full task text and requirements into prompts for implementer and reviewer subagents.
- Boundary markers: Uses logical headers to organize subagent prompts and explicitly instructs reviewers to verify code independently.
- Capability inventory: Subagents are granted broad permissions to modify the codebase, run tests, and commit changes.
- Sanitization: The architecture relies on multi-layered verification (self-review plus two external reviews) to identify and correct any malicious or incorrect instructions introduced via the task input.
- [SAFE]: No indicators of malicious intent, obfuscation, or unauthorized data access were found. The skill is designed with defensive patterns for agent orchestration.
Audit Metadata