handover-review

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface arising from its core functionality.
  • Ingestion points: External content is ingested via handover.read_artifact, handover.thread, and handover.annotations in SKILL.md.
  • Boundary markers: No delimiters or 'ignore' instructions are provided to isolate untrusted content from the agent's instructions.
  • Capability inventory: The skill can perform write actions including handover.comment, handover.annotate, handover.assign, and handover.update_comment as seen in SKILL.md.
  • Sanitization: There is no evidence of sanitization or validation of the retrieved content.
  • [SAFE]: The skill follows operational best practices by requiring identity verification through handover.whoami and emphasizing revision-anchored annotations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 08:29 PM
Security Audit — agent-trust-hub — handover-review