create-handoff
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to create handoff documents (YAML in
SKILL.mdand Markdown inSKILL.v6.md) that are explicitly intended to be read by the next agent session via a resume command. This creates a multi-step injection surface where malicious instructions could be persisted across sessions. - Ingestion points: The agent is instructed to summarize its current session context, including goals, decisions, findings, and next steps, into a structured file.
- Boundary markers: Absent. The templates do not include delimiters or instructions for the subsequent agent to ignore or sanitize instructions found within the handoff data.
- Capability inventory: The skill possesses the ability to write files to the filesystem and execute shell commands via
bashanduv run. - Sanitization: None. The content is interpolated directly into the templates without escaping or validation.
- [COMMAND_EXECUTION]: The skill executes several shell commands to manage session metadata and project state.
- Evidence:
SKILL.v6.mdexecutes a local script at~/.claude/scripts/spec_metadata.shand reads from~/.claude/state/braintrust_sessions/*.json. - Evidence: Both
SKILL.mdandSKILL.v6.mduseuv run pythonto executescripts/core/artifact_index.pyandartifact_mark.pylocated within the project'sopcdirectory. - Evidence: The skill uses
ls,sed,xargs, andgit rev-parseto dynamically determine file paths and session names, which are then passed to subsequent shell commands.
Audit Metadata