handoff

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill automatically ingests data from local artifacts and git history to resume context, which could allow instructions from a previous session to influence current agent behavior.
  • Ingestion points: The skill reads state from .agents/artifacts/HANDOFF.md, .agents/context/current.md, and session memory, and it reconstructs state using git history (status, log, and diff) via bash.
  • Boundary markers: The skill implements a strict directory-boundary matching protocol (defined in references/resumption-protocol.md) to prevent context bleed between projects, though it lacks verification of the content's intent.
  • Capability inventory: The skill has access to bash, view_file, and write_to_file tools across all operational modes.
  • Sanitization: No explicit sanitization or safety filtering is applied to the objectives, decisions, or instructions retrieved from the handoff artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 12:08 PM
Security Audit — agent-trust-hub — handoff