handoff
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill compacts conversation history into a handoff document designed for another agent to process. This creates a multi-step prompt injection surface where instructions embedded in the conversation history may be preserved in the summary.
- Ingestion points: The skill ingests the entire current conversation history to generate the summary.
- Boundary markers: The instructions do not define specific delimiters or "ignore embedded instructions" markers for the output document to protect the next agent.
- Capability inventory: The skill writes to the filesystem (OS temporary directory).
- Sanitization: While the skill explicitly requests redaction of sensitive credentials (API keys, passwords, PII), it does not include instructions to sanitize or escape instruction-like text within the conversation, which could lead the next agent to treat summarized user content as its own instructions.
- Suggested Skills Surface: The requirement to include a "suggested skills" section is particularly susceptible to manipulation, as an attacker could influence the current agent to suggest malicious or unintended tools for the next session.
Audit Metadata