helm-handoff
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface area detected. The skill ingests untrusted product briefs in Step 1 and passes them as context to the Apex agent in Step 3. Ingestion points: Product brief fields including goal, user_problem, and scope defined in SKILL.md. Boundary markers: Employs a structured 6-field box-drawing text schema for separation. Capability inventory: Access to Bash, Write, and WebFetch tools. Sanitization: No explicit filtering or sanitization of the brief data is performed before it is provided to the downstream agent.
Audit Metadata