session-handoff
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a workflow for ingesting session history and re-injecting it into future prompts, creating a surface for indirect prompt injection.
- Ingestion points: The skill instructions in
modules/two-phase-extraction.mddirect the agent to sweep the entire session transcript to identify threads for extraction. - Boundary markers: The schema defined in
modules/unit-schema.mddoes not specify the use of delimiters or instructions to ignore embedded commands within the captured units. - Capability inventory: The skill writes extracted data to a local file (
data/state/handoff_units.json). The+recallhook mentioned inSKILL.mdsubsequently retrieves this data and interpolates it back into the agent's prompt. - Sanitization: There is no evidence of filtering, sanitization, or validation of the text content stored in the
state,why, oropenfields to prevent the persistence of malicious instructions from the session transcript.
Audit Metadata