handoff

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements a security-conscious design by explicitly instructing the agent to redact sensitive information, including API keys, passwords, and personally identifiable information, before generating the output.
  • [COMMAND_EXECUTION]: The skill directs the agent to perform file system write operations to the operating system's temporary directory (outside the project workspace) to store the handoff document.
  • [PROMPT_INJECTION]: There is a surface for indirect prompt injection because the skill aggregates the conversation history (Ingestion point: SKILL.md) to generate a handoff. While it includes sanitization to redact sensitive info, it lacks explicit boundary markers to prevent malicious instructions within the conversation from influencing the next agent session. The generated summary is written to the system's temporary directory (Capability: SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 08:35 AM
Security Audit — agent-trust-hub — handoff