handoff

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes various system discovery commands via Python's subprocess.run with shell=True in handoff.py.
  • Evidence includes calls to git, rg 'TODO|FIXME|HACK' --vimgrep, and fd --max-depth 2.
  • These commands are used within a helper function run_command to collect repository status, commit history, and directory structure. While shell=True is used, the commands themselves are hardcoded or derived from safe internal lookups, minimizing the risk of arbitrary command injection from user inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — handoff