task-handoff
Warn
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requires and executes multiple command-line tools, including
git,ai-handoff,ai-coord, and macOS system utilitiespbcopyandpbpasteto manage state and publish handoff commands. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from repository instructions, task surfaces, and working-tree states to generate handoff files for subsequent agent sessions. Malicious content within a repository could be propagated into the handoff instructions without adequate isolation.
- Ingestion points: Ingests content from repository-level instructions, task-related files, and the current Git working-tree state.
- Boundary markers: Does not specify the use of delimiters or clear separation between the ingested untrusted data and the generated instructions for the receiving agent.
- Capability inventory: Possesses local file-write access, CLI tool execution capabilities, and access to the system clipboard.
- Sanitization: The instructions do not include specific steps to sanitize or escape repository content before interpolating it into the handoff draft.
- [DYNAMIC_EXECUTION]: The skill resolves local directory paths for other skills (e.g.,
~/.agents/skills/codex-handoff) and embeds these computed absolute paths into handoff files. It explicitly instructs the receiving session to load and execute the skill from that computed path during its initialization.
Audit Metadata