handoff

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided conversation history to generate summaries. This creates a surface for indirect prompt injection where malicious instructions within the conversation could be carried over into the handoff document, potentially influencing the behavior of the next agent. The skill lacks explicit delimiters or structural boundaries for the ingested content, though it does include specific instructions to redact sensitive information.
  • Ingestion points: Current conversation history and user-passed arguments processed by instructions in SKILL.md.
  • Boundary markers: Absent in SKILL.md.
  • Capability inventory: File system write capability to the OS temporary directory as defined in SKILL.md.
  • Sanitization: Instruction in SKILL.md to redact API keys, passwords, and personally identifiable information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:00 AM
Security Audit — agent-trust-hub — handoff