session-handoff
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow where the agent is prompted to "Review the note and execute the Next Action specified" from a handoff document. This creates an attack surface where instructions embedded in the project files or the note itself could influence agent behavior without validation.
- Ingestion points: Hand-off notes are intended to be pasted as the initial prompt in new agent sessions (documented in
context-hygiene-checklist.md). - Boundary markers: No delimiters or safety instructions are provided to scope the agent's interpretation of the 'Next Action' field.
- Capability inventory: The skill utilizes shell access (Git, test runners) and file system modification capabilities.
- Sanitization: No sanitization or verification mechanism exists for the contents of the handoff note before execution.
- [COMMAND_EXECUTION]: The skill instructs the agent to perform auditing and verification using standard development tools.
- Evidence: Instructions in
SKILL.mdandcontext-hygiene-checklist.mdcall for executinggit status -s,git diff --stat,pytest,npm test, andcargo checkto establish workspace state. - [EXTERNAL_DOWNLOADS]: The documentation suggests installing the skill via a remote package manager command.
- Evidence: The
README.mdincludes the commandnpx skills add alapha888/session-handoff-kit, which fetches the skill component from the npm registry.
Audit Metadata