task-handoff

Warn

Audited by Gen Agent Trust Hub on Oct 6, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires and executes multiple command-line tools, including git, ai-handoff, ai-coord, and macOS system utilities pbcopy and pbpaste to manage state and publish handoff commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from repository instructions, task surfaces, and working-tree states to generate handoff files for subsequent agent sessions. Malicious content within a repository could be propagated into the handoff instructions without adequate isolation.
  • Ingestion points: Ingests content from repository-level instructions, task-related files, and the current Git working-tree state.
  • Boundary markers: Does not specify the use of delimiters or clear separation between the ingested untrusted data and the generated instructions for the receiving agent.
  • Capability inventory: Possesses local file-write access, CLI tool execution capabilities, and access to the system clipboard.
  • Sanitization: The instructions do not include specific steps to sanitize or escape repository content before interpolating it into the handoff draft.
  • [DYNAMIC_EXECUTION]: The skill resolves local directory paths for other skills (e.g., ~/.agents/skills/codex-handoff) and embeds these computed absolute paths into handoff files. It explicitly instructs the receiving session to load and execute the skill from that computed path during its initialization.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 6, 2026, 02:58 PM