handoff
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill is instructed to save the generated handoff document to the operating system's temporary directory, moving conversation data outside the immediate workspace. This involves standard file system write operations.\n- [INDIRECT_PROMPT_INJECTION]: This skill ingests conversation history to generate summaries and skill suggestions, creating an attack surface for indirect prompt injection. Ingestion Point: conversation history; Boundary Markers: absent; Capability: file system write access to temp directory; Sanitization: the skill includes a specific instruction to redact credentials and PII before saving.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions include a security best practice by explicitly directing the agent to redact sensitive information, such as API keys, passwords, and personally identifiable information, before generating the summary document.
Audit Metadata