rc-handoff

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill contains explicit instructions to redact sensitive information, including API keys, passwords, and personally identifiable information (PII), which is a security best practice for session logging and handoffs.
  • [DATA_EXPOSURE]: The skill directs the agent to save the handoff document to the operating system's temporary directory rather than the local workspace. While this involves writing data outside the immediate project folder, it is consistent with the stated purpose of creating a temporary handoff artifact and minimizes clutter in the version-controlled workspace.
  • [INDIRECT_PROMPT_INJECTION]: As the skill involves summarizing a conversation (untrusted data) for consumption by a future agent, it possesses an inherent indirect prompt injection surface. However, the instruction to summarize and redact content acts as a natural filtering layer, and the risk is considered low and inherent to the intended functionality of session handoff.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 04:56 AM
Security Audit — agent-trust-hub — rc-handoff