The agent handoff should say what it cannot know.
That might be as important as what it can summarize.
If someone sends an agent to understand me from the public site, the agent needs boundaries.
It can read the public notes.
It can inspect the source trails.
It can see recurring themes.
It can understand what questions I seem to be circling.
But it should not pretend the public graph is the whole person.
It should not infer sensitive details that are not present.
It should not treat provisional notes as final doctrine.
It should not collapse old writing into current belief without checking the current lens.
That is part of the handoff.
The useful prompt is not only:
Here is what to read.
It is also:
Here is what this public context cannot tell you.