session-handoff

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses Git commands to inspect the repository state. The instructions direct the agent to run git status, git diff --stat, and git log --oneline -15 to collect evidence for the handoff document.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the repository and conversation history to generate its output, presenting a surface for indirect injection.
  • Ingestion points: The skill reads external data via git status, git diff, and git log, and incorporates quotes from the user's transcript.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore potentially malicious content embedded within the Git logs or transcript data.
  • Capability inventory: The skill has the capability to write files to the repository (e.g., HANDOFF.md or dated files in docs/handoff/).
  • Sanitization: No sanitization, escaping, or validation of the ingested Git output or transcript text is defined before it is written to the handoff file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 04:53 PM
Security Audit — agent-trust-hub — session-handoff