session-handoff
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes git commands including
git status,git branch, andgit logto extract the current repository state and commit history. It also performs a compliance audit that involves reading and modifying.jsonltelemetry logs.\n- [DATA_EXFILTRATION]: The skill instructs the agent to document infrastructure metadata such as AWS resource IDs, regions, and SSM parameter values. While stored locally, this practice increases the exposure of environment configuration and identifiers in plain-text documentation.\n- [PROMPT_INJECTION]: The skill processes untrusted conversation history to generate summaries and memory entries, creating a surface for indirect prompt injection.\n - Ingestion points: Processes conversation history and external
.jsonllog files.\n - Boundary markers: No delimiters or boundary markers are specified to distinguish between developer instructions and potentially malicious data in the conversation history.\n
- Capability inventory: Includes file system writes (
CHANGELOG.md,session-handoff.md), shell command execution, and automated invocation of theauto-memoryskill.\n - Sanitization: No sanitization or verification steps are defined for the content extracted from the history before it is written to the project's permanent memory or changelog.
Audit Metadata