handoff-report

Fail

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The instructions in Section 2 ('Establish what landed') explicitly request the agent to report any 'secret set' created during the task. This guidance can lead to the accidental exposure of sensitive API keys, passwords, or authentication tokens within the generated report, which is then printed or saved to a project board.- [COMMAND_EXECUTION]: Section 3 ('Report the verification you ran') directs the agent to take commands from external, potentially untrusted sources such as 'the handoff's validation section' or 'the repository's own manifests' and provide their results. This implies the execution of arbitrary commands defined within these external files, posing a significant risk of malicious code execution.- [INDIRECT_PROMPT_INJECTION]: The skill aggregates data from the repository and tool outputs into a final report, presenting an attack surface for indirect prompt injection.
  • Ingestion points: Git diffs, terminal command outputs, and repository manifest files (SKILL.md).
  • Boundary markers: The skill does not provide specific instructions to use delimiters or ignore instructions that may be embedded in the data being summarized.
  • Capability inventory: The skill includes the ability to write data to an external location using the 'project-board' tool (SKILL.md).
  • Sanitization: There are no requirements to sanitize or validate the content retrieved from the repository before it is included in the output report.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 14, 2026, 07:20 AM
Security Audit — agent-trust-hub — handoff-report