subagent-development
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a multi-stage development workflow with defined roles (Implementer, Spec Reviewer, Quality Reviewer), which promotes isolation and verified changes.
- [SAFE]: Mandatory human-in-the-loop control is integrated into the workflow; the skill is instructed to present the task list to the user and wait for approval before proceeding with execution.
- [SAFE]: The code quality reviewer prompt (reference/code-quality-reviewer-prompt.md) explicitly includes a security review step, checking for vulnerabilities like SQL injection, secret exposure, and path traversal.
- [SAFE]: Subagents are dispatched with fresh, task-specific contexts, which prevents context drift and reduces the attack surface for accidental or intentional instruction leakage across tasks.
Audit Metadata