handoff

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill creates a 'suggested skills' section intended for a subsequent agent, establishing an indirect prompt injection surface. 1. Ingestion points: Handoff documents consumed by fresh agents. 2. Boundary markers: None. 3. Capability inventory: Subsequent agents have skill execution permissions. 4. Sanitization: No validation of suggestions.
  • [COMMAND_EXECUTION]: The agent is instructed to write files to the OS temporary directory ('Save to the temporary directory of the user's OS'), potentially bypassing workspace-scoped security boundaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 12:22 PM
Security Audit — agent-trust-hub — handoff