ce-handoff
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell script blocks to resolve and create managed storage directories in references/create.md and references/resume.md. These commands are defensive, checking for symlink attacks and enforcing strict ownership and permissions (umask 077 and chmod 700) to ensure that session data remains private to the current user.
- [INDIRECT_PROMPT_INJECTION]: The skill manages a surface for indirect prompt injection by design, as it resumes context from external artifacts. It implements robust security controls to mitigate this risk:
- Ingestion points: The skill reads user-selected files, URLs, or discovered Markdown files in references/resume.md.
- Boundary markers: Explicit instructions in SKILL.md and references/resume.md mandate that the agent treat the source's metadata and body as untrusted context and not as instructions, preventing the handoff content from hijacking agent behavior.
- Capability inventory: The skill uses shell blocks for local environment discovery and performs file read/write operations for state management.
- Sanitization: The skill requires the agent to redact secrets and credentials before writing a handoff and mandates JSON-compatible YAML double-quoting for metadata to prevent injection during parsing.
Audit Metadata