handover

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes several shell commands to gather project metadata, including git rev-parse, git branch, git log, git worktree list, git status, gh pr list, and gh issue list. These are standard diagnostic commands used to build the handover context.
  • [DATA_EXFILTRATION]: The skill collects sensitive repository information, including branch names, recent logs, worktree paths, and GitHub Issue/PR details. While this data is intended for a local handover document (docs/handover/), the aggregation of this metadata represents a data exposure surface if the output is shared externally.
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8) because it ingests untrusted data from external sources without explicit sanitization or boundary markers.
  • Ingestion points: Data enters the context via git log, gh pr list, and gh issue list (SKILL.md, Procedure Step 1).
  • Boundary markers: The instructions do not specify the use of delimiters (e.g., XML tags or triple backticks) to isolate the collected data from the agent's instructions during document generation.
  • Capability inventory: The skill has the capability to execute shell commands and write to the local file system (SKILL.md, Procedure Step 5).
  • Sanitization: There is no mention of escaping, filtering, or validating the content retrieved from commit messages, PR titles, or issue labels.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 05:07 PM
Security Audit — agent-trust-hub — handover