ce-handoff

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell script blocks to resolve and create managed storage directories in references/create.md and references/resume.md. These commands are defensive, checking for symlink attacks and enforcing strict ownership and permissions (umask 077 and chmod 700) to ensure that session data remains private to the current user.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages a surface for indirect prompt injection by design, as it resumes context from external artifacts. It implements robust security controls to mitigate this risk:
  • Ingestion points: The skill reads user-selected files, URLs, or discovered Markdown files in references/resume.md.
  • Boundary markers: Explicit instructions in SKILL.md and references/resume.md mandate that the agent treat the source's metadata and body as untrusted context and not as instructions, preventing the handoff content from hijacking agent behavior.
  • Capability inventory: The skill uses shell blocks for local environment discovery and performs file read/write operations for state management.
  • Sanitization: The skill requires the agent to redact secrets and credentials before writing a handoff and mandates JSON-compatible YAML double-quoting for metadata to prevent injection during parsing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 04:28 PM
Security Audit — agent-trust-hub — ce-handoff