exploration-handoff
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes user-provided files from the
exploration/directory, which presents an indirect prompt injection surface. - Ingestion points: Artifact files (e.g., session briefs, BRDs) located in the
exploration/directory. - Boundary markers: No explicit delimiters are specified for the ingested content in the read operations.
- Capability inventory: The skill is permitted to use
Bash,Read, andWritetools as defined in the frontmatter. - Sanitization: The skill relies on agent synthesis logic and iterative user review rather than automated sanitization to manage potentially malicious content in source files.
Audit Metadata