handoff
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data when reading from a file path provided in the argument (a prior handoff file). This content could contain malicious instructions meant to influence the agent's behavior or output when the fresh session is initialized.
- Ingestion points: The
SKILL.mdinstructions allow reading from a prior handoff file path provided as an argument. - Boundary markers: The instructions do not define specific delimiters or boundary markers to separate the content of the prior handoff from the agent's current task instructions.
- Capability inventory: The skill performs file system read and write operations to
~/.manifest-dev/handoffs/and potentially other writable temporary paths. - Sanitization: The skill explicitly instructs the agent to redact credentials, tokens, and personal data from the output payload, which serves as a mitigation for data exposure.
Audit Metadata