subagent-driven-development
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill describes a structured management process for software development using isolated subagents for individual tasks.
- [DATA_EXPOSURE]: The skill involves reading project-specific implementation plans and source code for the purpose of review and implementation. These operations are restricted to the local development environment and do not target sensitive system paths or credentials.
- [PROMPT_INJECTION]: The provided prompt templates for the Implementer and Reviewer roles use well-defined structures and clear instructions. The Spec Compliance Reviewer specifically includes instructions to maintain a skeptical posture toward the Implementer's report, which serves as a safeguard against inaccurate or misleading agent outputs.
- [COMMAND_EXECUTION]: The workflow involves standard development tools and git operations (represented by SHAs and specific tool references like
superpowers:finishing-a-development-branch). There are no instances of arbitrary command execution or privilege escalation attempts.
Audit Metadata