claude-handoff

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a shell command (claude --bg --name "<name>" "<summary>") using strings generated from the current conversation and user arguments. This creates a surface for command injection if the agent fails to properly quote or sanitize the generated parameters. Evidence: Found in SKILL.md: "claude --bg --name \"<descriptive name>\" \"<handoff summary>\"".
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the conversation history and user arguments to create the prompt for a subsequent agent session, potentially carrying over malicious instructions from external data read during the session. 1. Ingestion points: Conversation history and user-provided arguments in SKILL.md. 2. Boundary markers: None present to delimit untrusted content or warn the next agent about embedded instructions. 3. Capability inventory: Shell command execution via the claude CLI. 4. Sanitization: While the instructions explicitly require redacting sensitive credentials (API keys, passwords), no validation or sanitization is performed to prevent malicious instructions in the conversation history from influencing the next agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:23 PM
Security Audit — agent-trust-hub — claude-handoff