exploration-handoff

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes user-provided files from the exploration/ directory, which presents an indirect prompt injection surface.
  • Ingestion points: Artifact files (e.g., session briefs, BRDs) located in the exploration/ directory.
  • Boundary markers: No explicit delimiters are specified for the ingested content in the read operations.
  • Capability inventory: The skill is permitted to use Bash, Read, and Write tools as defined in the frontmatter.
  • Sanitization: The skill relies on agent synthesis logic and iterative user review rather than automated sanitization to manage potentially malicious content in source files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 06:09 PM