skills/wakqasahmed/skills/handover/Gen Agent Trust Hub

handover

Pass

Audited by Gen Agent Trust Hub on Jul 23, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is primarily instructional and provides a template for session summarization. It lacks any executable code or risky automation.
  • [SAFE]: The skill includes a clear security policy for sensitive data, instructing the agent to redact API keys, passwords, and PII before generating the handover document.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: While the skill involves summarization and publishing to GitHub issues, it explicitly mandates the redaction of credentials and sensitive paths. The intended behavior (posting to the user's own issues) is part of its documented functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes the conversation history, which is a potential surface for indirect injection if the history contains malicious content.
  • Ingestion points: Full conversation history and plan files (SKILL.md).
  • Boundary markers: Uses a strict structured markdown template for output.
  • Capability inventory: File system access (writing to temp directory) and GitHub issue interaction.
  • Sanitization: Explicit instructions to redact secrets and PII (Credential details: [redacted]).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 23, 2026, 07:13 AM
Security Audit — agent-trust-hub — handover