handoff

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by processing untrusted conversation history. However, it is evaluated as safe due to strong mitigation instructions.\n
  • Ingestion points: Conversation context and user-provided arguments processed in SKILL.md.\n
  • Boundary markers: None explicitly defined.\n
  • Capability inventory: File system write access to the OS temporary directory.\n
  • Sanitization: Explicitly mandates the redaction of sensitive credentials and PII before document generation.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: No data exposure or exfiltration issues were identified. The skill follows secret management best practices by instructing the agent to redact credentials rather than exposing them. Storage is limited to a local temporary directory rather than a remote server.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 03:09 AM
Security Audit — agent-trust-hub — handoff