handoff
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes the current conversation history as its primary data source, which is an untrusted ingestion point.
- Ingestion points: conversation history referenced in
SKILL.md. - Boundary markers: The instructions lack explicit delimiters for separating the conversation data from the summary logic, though it specifies a structured output format.
- Capability inventory: The skill relies on the agent's ability to summarize text and write files to the operating system's temporary directory.
- Sanitization: The skill includes a proactive safety directive to "Redact any sensitive information, such as API keys, passwords, or personally identifiable information."
Audit Metadata