handoff

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill summarizes the current conversation history, which contains untrusted user input, to be read by a future agent session. This creates a surface where malicious instructions in the current chat could be persisted and influence the next session. * Ingestion points: Conversation context and user-provided arguments in SKILL.md. * Boundary markers: Absent. No specific delimiters are used to wrap the summarized content. * Capability inventory: Writing files to the operating system's temporary directory. * Sanitization: The instructions mandate redaction of API keys, passwords, and personally identifiable information.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The instructions explicitly direct the agent to save the handoff document to the operating system's temporary directory instead of the current workspace, which moves information outside of defined project boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 06:03 PM
Security Audit — agent-trust-hub — handoff