resume-handoff

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests content from external files (handoffs, research notes, and plans) and uses this untrusted data to synthesize its analysis and generate prompts for specialist sub-agents.
  • Ingestion points: The skill reads files from paths such as thoughts/shared/handoffs/, thoughts/shared/plans/, and thoughts/shared/research/, as well as any file path provided by the user.
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are utilized when processing the content of these documents; the skill is explicitly instructed to read the documents "FULLY".
  • Capability inventory: The skill possesses the ability to spawn specialist sub-agents via the Task tool (e.g., kraken, spark, sleuth), write task lists via TodoWrite, and read arbitrary files using the Read tool.
  • Sanitization: There is no evidence of sanitization, validation, or filtering of the external content before it is interpolated into prompts for the AI or the specialist agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:11 PM
Security Audit — agent-trust-hub — resume-handoff