handoff

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data when reading from a file path provided in the argument (a prior handoff file). This content could contain malicious instructions meant to influence the agent's behavior or output when the fresh session is initialized.
  • Ingestion points: The SKILL.md instructions allow reading from a prior handoff file path provided as an argument.
  • Boundary markers: The instructions do not define specific delimiters or boundary markers to separate the content of the prior handoff from the agent's current task instructions.
  • Capability inventory: The skill performs file system read and write operations to ~/.manifest-dev/handoffs/ and potentially other writable temporary paths.
  • Sanitization: The skill explicitly instructs the agent to redact credentials, tokens, and personal data from the output payload, which serves as a mitigation for data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 08:34 PM
Security Audit — agent-trust-hub — handoff