handoff
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes conversation history which acts as a surface for indirect prompt injection. 1. Ingestion points: current conversation history. 2. Boundary markers: absent for the summary document content. 3. Capability inventory: file write access to the user's OS temporary directory. 4. Sanitization: instructions explicitly mandate redacting API keys, passwords, and PII before saving.
- [SAFE]: The skill includes security best practices by instructing the agent to redact sensitive information before saving the summary and uses the system's temporary directory for transient data storage.
Audit Metadata