session-handoff

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where the agent is prompted to "Review the note and execute the Next Action specified" from a handoff document. This creates an attack surface where instructions embedded in the project files or the note itself could influence agent behavior without validation.
  • Ingestion points: Hand-off notes are intended to be pasted as the initial prompt in new agent sessions (documented in context-hygiene-checklist.md).
  • Boundary markers: No delimiters or safety instructions are provided to scope the agent's interpretation of the 'Next Action' field.
  • Capability inventory: The skill utilizes shell access (Git, test runners) and file system modification capabilities.
  • Sanitization: No sanitization or verification mechanism exists for the contents of the handoff note before execution.
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform auditing and verification using standard development tools.
  • Evidence: Instructions in SKILL.md and context-hygiene-checklist.md call for executing git status -s, git diff --stat, pytest, npm test, and cargo check to establish workspace state.
  • [EXTERNAL_DOWNLOADS]: The documentation suggests installing the skill via a remote package manager command.
  • Evidence: The README.md includes the command npx skills add alapha888/session-handoff-kit, which fetches the skill component from the npm registry.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 08:43 AM
Security Audit — agent-trust-hub — session-handoff