handoff
Pass
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by processing untrusted conversation history. However, it is evaluated as safe due to strong mitigation instructions.\n
- Ingestion points: Conversation context and user-provided arguments processed in SKILL.md.\n
- Boundary markers: None explicitly defined.\n
- Capability inventory: File system write access to the OS temporary directory.\n
- Sanitization: Explicitly mandates the redaction of sensitive credentials and PII before document generation.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: No data exposure or exfiltration issues were identified. The skill follows secret management best practices by instructing the agent to redact credentials rather than exposing them. Storage is limited to a local temporary directory rather than a remote server.
Audit Metadata