handoff
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted conversation history and writes it to the local filesystem, which could allow malicious instructions in the conversation to persist in the generated documentation.
- Ingestion point: Conversation context (SKILL.md).
- Boundary markers: Absent.
- Capability inventory: Writing to
docs/handoff/. - Sanitization: Instructions to redact sensitive data (API keys, passwords, PII) are present.
Audit Metadata