subagent-delegation

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of markdown documentation and instructions for the agent's behavior. It does not contain any executable scripts, shell commands, or binary files.\n- [SAFE]: The protocol defines clear boundaries for subagent invocation, emphasizing least-privilege tool access and workspace isolation modes (inherit, branch, share) to prevent data corruption during concurrent work.\n- [SAFE]: The 'Inline Fallback' section describes a user-facing notification for older platform versions, which is a standard UI/UX practice and does not involve any security bypasses.\n- [SAFE]: The skill references internal scripts like scripts/validate-agents.ps1/.sh for validation, but these are described as architectural enforcement tools rather than providing a vector for remote code execution or privilege escalation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:51 AM
Security Audit — agent-trust-hub — subagent-delegation