handoff
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes several shell scripts (
handoff-lib.sh,handoff-path.sh,check-handoff.sh) to manage the handoff lifecycle. These scripts execute standard system commands (e.g.,git,mkdir,ln,grep,sed) to manage project-scoped directories and symlinks. All shell variables derived from external inputs, such as project paths, are consistently double-quoted to prevent command injection. - [INDIRECT_PROMPT_INJECTION]: The skill's core functionality involves reading and processing handoff files generated in previous sessions, which represents an indirect prompt injection surface. A malicious actor with access to the user's filesystem could theoretically craft a handoff file to influence agent behavior.
- Ingestion points: The
check-handoff.shhook andhandoff-path.sh --latestcommand read metadata (like the 'Goal' field) and instructions from existingclaude-handoff-*.mdfiles stored in~/.claude/handoff/. - Boundary markers: The skill prepends a sensitivity header (
<!-- HIGHLY SENSITIVE. Do not share this file. -->) to all handoff files as a visual and programmatic indicator of the file's nature. - Capability inventory: The skill has the capability to write files to the user's home directory, create symlinks within the project tree, modify local Git configuration (
.git/info/exclude), and invoke other local scripts. - Sanitization: The skill implements a proactive defense via
handoff_scan_secrets, which uses a comprehensive set of regular expressions to scan handoff drafts for sensitive information (e.g., AWS keys, GitHub tokens, private keys) before they are committed to the store. - [DYNAMIC_EXECUTION]: The skill performs cross-skill integration by invoking a Python script from the
project-mapskill (python3 ~/.claude/skills/project-map/build-map.py) to verify the status of the codebase map. This is a legitimate use of modular skill architecture within the agent's environment.
Audit Metadata