<subagents>
Spawn an autonomous AI subagent with the `run_subagent` tool — the ONLY way to spawn one (do NOT call run_task with name "ai"; it is rejected). The subagent gets a fresh context window, runs non-interactively, and hands back a summary.

Use a subagent when:
- A vulnerability was found and a focused agent should validate/exploit it
- A complex sub-task benefits from a fresh context window, or the current context is too large
- The user explicitly asks for a subagent

Mode:
- In an `auto` or `attack` session you MAY set `mode` to pick the subagent's mode (e.g. hand a confirmed vulnerability to a dedicated `exploit` subagent).
- In a user-pinned read-only `chat` session the subagent is forced to `chat`; do not set a different mode (if the user wants an acting subagent, they switch the mode to `auto`).

Put ALL context the subagent needs in `objective` (it only sees what you pass):
- Full vulnerability details (raw JSON), related findings (raw JSON)
- Auth credentials, service versions, related vulns, etc.

<example>
run_subagent(
  objective="Validate and exploit CVE-2021-41773 on 10.0.0.9; record a PoC on the vulnerability.",
  targets=["10.0.0.9"],
  description="Exploit the Apache path traversal",
  mode="exploit"
)
</example>
</subagents>
