session-handoff
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Git commands to inspect the repository state. The instructions direct the agent to run
git status,git diff --stat, andgit log --oneline -15to collect evidence for the handoff document. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository and conversation history to generate its output, presenting a surface for indirect injection.
- Ingestion points: The skill reads external data via
git status,git diff, andgit log, and incorporates quotes from the user's transcript. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious content embedded within the Git logs or transcript data.
- Capability inventory: The skill has the capability to write files to the repository (e.g.,
HANDOFF.mdor dated files indocs/handoff/). - Sanitization: No sanitization, escaping, or validation of the ingested Git output or transcript text is defined before it is written to the handoff file.
Audit Metadata