create-handoff

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to create handoff documents (YAML in SKILL.md and Markdown in SKILL.v6.md) that are explicitly intended to be read by the next agent session via a resume command. This creates a multi-step injection surface where malicious instructions could be persisted across sessions.
  • Ingestion points: The agent is instructed to summarize its current session context, including goals, decisions, findings, and next steps, into a structured file.
  • Boundary markers: Absent. The templates do not include delimiters or instructions for the subsequent agent to ignore or sanitize instructions found within the handoff data.
  • Capability inventory: The skill possesses the ability to write files to the filesystem and execute shell commands via bash and uv run.
  • Sanitization: None. The content is interpolated directly into the templates without escaping or validation.
  • [COMMAND_EXECUTION]: The skill executes several shell commands to manage session metadata and project state.
  • Evidence: SKILL.v6.md executes a local script at ~/.claude/scripts/spec_metadata.sh and reads from ~/.claude/state/braintrust_sessions/*.json.
  • Evidence: Both SKILL.md and SKILL.v6.md use uv run python to execute scripts/core/artifact_index.py and artifact_mark.py located within the project's opc directory.
  • Evidence: The skill uses ls, sed, xargs, and git rev-parse to dynamically determine file paths and session names, which are then passed to subsequent shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 05:10 PM
Security Audit — agent-trust-hub — create-handoff