handoff
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected. The skill is entirely composed of natural language instructions and configuration metadata.
- [INDIRECT_PROMPT_INJECTION]: The skill identifies an attack surface where untrusted data from the repository is processed by the agent.
- Ingestion points: SKILL.md (Workflow steps 2, 3, 5) indicates the agent reads from context, recent edits, selected files, branches, issues, and PRs.
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the handoff template.
- Capability inventory: The skill itself does not define or use any shell, subprocess, or network capabilities.
- Sanitization: No input validation or sanitization of ingested content is performed.
Audit Metadata