handoff
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill creates a handoff document based on untrusted session data and user arguments, which is intended to be consumed by another agent, forming a multi-step chain.
- Ingestion points: Uses the current session context and user-supplied arguments as input (SKILL.md).
- Boundary markers: The skill does not define specific boundary markers or delimiters for the generated summary text.
- Capability inventory: The agent is instructed to perform a file-write operation to the operating system's temporary directory.
- Sanitization: The instructions explicitly mandate the anonymization of sensitive data such as API keys, passwords, and PII before writing to the document.
Audit Metadata