subagent-driven-development

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment presents a coherent, governance-oriented workflow for subagent-driven development with gated reviews. It is broadly benign in intent and proportional in scope, but introduces data-flow and trust considerations around inter-agent communications. The primary concerns are potential data leakage to external subagents and the need for clear policy on data handling, prompt isolation, and auditability of actions taken by subagents. No code-level malicious behavior is evident, but the orchestration pattern should be reviewed for data governance and consent controls before deployment.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:25 PM
Package URL
pkg:socket/skills-sh/vibemastery%2Ftoolkit%2Fsubagent-driven-development%2F@671193fad13ce72be62027584265038e972243d0