handoff
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted conversation history to generate summaries, which provides a surface for indirect prompt injection.
- Ingestion points: The entire current conversation history and user-supplied arguments are used as input for the handoff document.
- Boundary markers: No specific delimiters or boundary markers are instructed for the output to distinguish summarized user content from instructions for the next agent.
- Capability inventory: The skill uses the 'Write' tool to save output to the OS temporary directory and the 'Read', 'Grep', and 'Glob' tools to reference existing project artifacts.
- Sanitization: The skill includes a clear and mandatory security instruction for the agent to redact API keys, passwords, and personally identifiable information before writing the handoff document.
Audit Metadata