handoff
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes conversation history, which serves as a surface for indirect prompt injection.
- Ingestion points: The agent processes the current conversation as input for the handoff document.
- Boundary markers: The skill relies on instructional rules rather than machine-delimited boundaries for untrusted data.
- Capability inventory: The skill allows the agent to write a summary file to the OS temporary directory.
- Sanitization: Rule 1 explicitly mandates the redaction of API keys, passwords, tokens, and PII, significantly mitigating data exposure risks.
- [EXTERNAL_DOWNLOADS]: The documentation references a well-known GitHub repository for attribution. This is a neutral reference and does not involve automated downloads, dependency installation, or remote code execution.
Audit Metadata