subagents

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data by subagents, which may include files or URLs provided in the task description. This creates an attack surface where malicious instructions embedded in processed content could influence subagent behavior or the parent's synthesis of the report.
  • Ingestion points: Subagent tasks can include files and URLs for processing as defined in SKILL.md.
  • Boundary markers: The skill suggests including constraints in the task description to guide the subagent, but does not define strict delimiters or instructions to ignore embedded commands in external data.
  • Capability inventory: Subagents operate with the same tools as the parent agent, which includes file system access and editing capabilities as mentioned in SKILL.md.
  • Sanitization: No specific sanitization or validation protocols for the external content processed by subagents are described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 09:31 AM
Security Audit — agent-trust-hub — subagents