subagent-development

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a multi-stage development workflow with defined roles (Implementer, Spec Reviewer, Quality Reviewer), which promotes isolation and verified changes.
  • [SAFE]: Mandatory human-in-the-loop control is integrated into the workflow; the skill is instructed to present the task list to the user and wait for approval before proceeding with execution.
  • [SAFE]: The code quality reviewer prompt (reference/code-quality-reviewer-prompt.md) explicitly includes a security review step, checking for vulnerabilities like SQL injection, secret exposure, and path traversal.
  • [SAFE]: Subagents are dispatched with fresh, task-specific contexts, which prevents context drift and reduces the attack surface for accidental or intentional instruction leakage across tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 12:05 AM
Security Audit — agent-trust-hub — subagent-development