engagement-handoff
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted session data, including tool outputs and findings, which could contain malicious instructions designed to subvert agent behavior.
- Ingestion points: The skill reviews findings, tool runs, and target data from the session (SKILL.md).
- Boundary markers: No explicit delimiters or instructions to ignore embedded commands are included in the document template (references/handoff-template.md).
- Capability inventory: The skill has the ability to write generated content to the local file system at HANDOFF.md (SKILL.md).
- Sanitization: The skill lacks automated sanitization or filtering for the data it processes, relying instead on a high-level instruction to manually exclude credentials.
Audit Metadata