handoff
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill instructs the agent to write session summaries to the OS temporary directory outside of the project workspace. While this is intended for cross-session handoffs, writing sensitive session context to shared system areas increases the risk of data exposure to other users or processes on the host system.
- [INDIRECT_PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it ingests untrusted data from the current session to generate instructions for a future agent.
- Ingestion points: Reads current session state, decisions, and user-provided arguments from SKILL.md.
- Boundary markers: The skill does not instruct the agent to use specific delimiters or include warnings for the next agent to ignore embedded instructions within the handoff document.
- Capability inventory: The skill uses file-writing capabilities to save the document to the system's temporary directory.
- Sanitization: The skill explicitly requests the redaction of secrets (API keys, passwords, tokens, PII), which mitigates but does not eliminate the risk of processing malicious instructions inserted into the session context.
Audit Metadata