context-handoff
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes conversation history which may contain untrusted data. 1. Ingestion points: Full conversation history processed during handoff in the SKILL.md instructions. 2. Boundary markers: The distilled summary is wrapped in a markdown code block for copying, but no specific instructions to ignore instructions within the conversation history are provided. 3. Capability inventory: The skill is behavioral and does not request tool access, network access, or file system permissions. 4. Sanitization: No sanitization or validation is performed on the ingested conversation data before it is distilled into the summary block.
Audit Metadata