handoff
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute the shell command
mktemp -t handoff-XXXXXX.mdto generate a file path for saving the handoff summary. - [DATA_EXFILTRATION]: The skill encourages the agent to reference internal artifacts by path or URL, which may lead to the unintended disclosure of sensitive local file paths or internal resource locations in the final document.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it transforms untrusted conversation data into instructions for a subsequent agent session. 1. Ingestion points: Conversation history and user-supplied arguments (SKILL.md). 2. Boundary markers: No delimiters or isolation warnings are used to separate the summary from agent instructions. 3. Capability inventory: The agent has shell execution (
mktemp) and file system access capabilities. 4. Sanitization: No filtering or validation of the ingested conversation is performed. Additionally, the instruction to 'read the file before you write to it' after usingmktempis an anomalous logic pattern that could be used to influence agent behavior through externally controlled file content.
Audit Metadata