handoff

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill is instructed to save the generated handoff document to the operating system's temporary directory, moving conversation data outside the immediate workspace. This involves standard file system write operations.\n- [INDIRECT_PROMPT_INJECTION]: This skill ingests conversation history to generate summaries and skill suggestions, creating an attack surface for indirect prompt injection. Ingestion Point: conversation history; Boundary Markers: absent; Capability: file system write access to temp directory; Sanitization: the skill includes a specific instruction to redact credentials and PII before saving.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions include a security best practice by explicitly directing the agent to redact sensitive information, such as API keys, passwords, and personally identifiable information, before generating the summary document.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 10:28 AM
Security Audit — agent-trust-hub — handoff