skills/rohitg00/agentmemory/handoff/Gen Agent Trust Hub

handoff

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill retrieves and processes data from previous agent sessions via memory tools without established safety boundaries.
  • Ingestion points: Session summaries, narrative observations, and recalled concepts from the memory_sessions and memory_recall tool outputs (SKILL.md, Workflow steps 3 and 4).
  • Boundary markers: Absent. The instructions do not provide delimiters or warnings to the agent to disregard potential instructions embedded in the historical session data.
  • Capability inventory: The skill uses memory retrieval tools; however, the agent executing the skill may possess broader capabilities (file system access, network access, etc.) that could be targeted by instructions found in the session history.
  • Sanitization: Absent. The skill explicitly searches for "unanswered questions" in the narrative and leads with them, which could be abused to prioritize malicious instructions if they are phrased as questions in a past session.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 10:39 AM
Security Audit — agent-trust-hub — handoff