session-handoff
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes repository state, logs, and plans to generate a new prompt file, creating a surface for indirect prompt injection. 1. Ingestion points: Reads repository state, file contents, logs, and user instructions as specified in SKILL.md. 2. Boundary markers: Uses standard markdown headers in the template without explicit isolation delimiters for external data. 3. Capability inventory: Performs file writing (handoff.md) and suggests command execution for the successor agent. 4. Sanitization: Instructs the agent to proactively remove secrets, tokens, and personal data from the output.
- [EXTERNAL_DOWNLOADS]: Documentation in references/source-notes.md includes links to resources from trusted organizations such as Anthropic, OpenAI, Microsoft, and LangChain. These references are for documentation purposes and do not involve remote code execution.
Audit Metadata