handoff

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the conversation history and writes files to the operating system, creating an indirect prompt injection surface.
  • Ingestion points: The skill processes the "current conversation," which may contain inputs from untrusted sources (SKILL.md).
  • Boundary markers: No explicit delimiters or boundary markers are defined in the instructions to isolate the summarized data from the agent's instructions.
  • Capability inventory: The skill utilizes file-writing capabilities to "Save to the temporary directory of the user's OS" (SKILL.md).
  • Sanitization: The skill includes an explicit instruction to "Redact any sensitive information, such as API keys, passwords, or personally identifiable information" (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:23 PM
Security Audit — agent-trust-hub — handoff