session-handoff

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes repository state, logs, and plans to generate a new prompt file, creating a surface for indirect prompt injection. 1. Ingestion points: Reads repository state, file contents, logs, and user instructions as specified in SKILL.md. 2. Boundary markers: Uses standard markdown headers in the template without explicit isolation delimiters for external data. 3. Capability inventory: Performs file writing (handoff.md) and suggests command execution for the successor agent. 4. Sanitization: Instructs the agent to proactively remove secrets, tokens, and personal data from the output.
  • [EXTERNAL_DOWNLOADS]: Documentation in references/source-notes.md includes links to resources from trusted organizations such as Anthropic, OpenAI, Microsoft, and LangChain. These references are for documentation purposes and do not involve remote code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 05:37 AM
Security Audit — agent-trust-hub — session-handoff