subagent-development
Warn
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
- Privilege Escalation (MEDIUM): The document provides instructions on using the
permissionModefrontmatter property to disable user confirmation for sensitive tasks. Specifically, thebypassPermissionsvalue allows an agent to skip all permission prompts, whileacceptEditsallows it to modify files without intervention, bypassing the agent's primary safety controls. - Metadata Poisoning (LOW): The documentation frames undocumented and potentially unsafe security bypasses as 'features' discovered through 'internal patterns,' which may encourage users to adopt insecure configurations without fully understanding the risks.
Audit Metadata