vibe-handoff
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to inspect the environment for branch information, revision history, and working-tree changes as part of its project analysis functionality.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from local project files which could contain malicious instructions designed to influence the agent's behavior during summary generation.
- Ingestion points: Reads files such as MEMORY.md, manifests, decision logs, and outputs from available check results within the workspace.
- Boundary markers: Absent. The instructions do not define specific delimiters or isolation techniques to separate data from instructions when processing file content.
- Capability inventory: The skill has access to shell execution (Bash), file creation (Write), and file modification (Edit) tools.
- Sanitization: While the instructions mandate the exclusion of secrets and personal data, there is no technical sanitization or validation performed on the text read from project files before it is processed by the agent.
Audit Metadata