session-handoff

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for ingesting session history and re-injecting it into future prompts, creating a surface for indirect prompt injection.
  • Ingestion points: The skill instructions in modules/two-phase-extraction.md direct the agent to sweep the entire session transcript to identify threads for extraction.
  • Boundary markers: The schema defined in modules/unit-schema.md does not specify the use of delimiters or instructions to ignore embedded commands within the captured units.
  • Capability inventory: The skill writes extracted data to a local file (data/state/handoff_units.json). The +recall hook mentioned in SKILL.md subsequently retrieves this data and interpolates it back into the agent's prompt.
  • Sanitization: There is no evidence of filtering, sanitization, or validation of the text content stored in the state, why, or open fields to prevent the persistence of malicious instructions from the session transcript.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:05 AM
Security Audit — agent-trust-hub — session-handoff