From 1312572fa140367010978f20129543c71052c281 Mon Sep 17 00:00:00 2001 From: Arpit Chakladar Date: Sun, 27 Sep 2026 19:06:55 +0530 Subject: feat(development/pi-coding-agent): added instructions on using subagents --- .../development/pi-coding-agent/skills/security-review/SKILL.md | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) (limited to 'modules/development/pi-coding-agent/skills/security-review/SKILL.md') diff --git a/modules/development/pi-coding-agent/skills/security-review/SKILL.md b/modules/development/pi-coding-agent/skills/security-review/SKILL.md index 0b2d307..3f534ab 100644 --- a/modules/development/pi-coding-agent/skills/security-review/SKILL.md +++ b/modules/development/pi-coding-agent/skills/security-review/SKILL.md @@ -7,6 +7,13 @@ description: "Look for secrets, injection, unsafe shell execution, auth/authz mi Look for secrets, injection, unsafe shell execution, auth/authz mistakes, dependency risks, path traversal, SSRF, insecure defaults, etc. +## Subagents +When you need to delegate sub‑tasks, use the `pi-subagents` skill. + +**Example:** For a security audit, run a **scout** to scan for injection vulnerabilities in the input validators, another **scout** to review authentication flows for authz mistakes, and a **reviewer** to check for path traversal and SSRF in file-handling code—all in parallel. + +*You may adapt the delegation pattern to fit the exact requirements of the codebase.* + ## Checklist ### Secrets & Credentials @@ -47,4 +54,4 @@ Look for secrets, injection, unsafe shell execution, auth/authz mistakes, depend ### Insecure Defaults - [ ] Secure defaults enabled - [ ] Debug endpoints disabled -- [ ] Proper CORS configuration \ No newline at end of file +- [ ] Proper CORS configuration -- cgit v1.2.3