handoff-to-worktree

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing shell commands via cmux and git to manage development workspaces and repository worktrees. It constructs strings to launch fresh claude instances with specific instructions.
  • [DYNAMIC_EXECUTION]: The skill uses shell utilities to decode the CMUX_AGENT_LAUNCH_ARGV_B64 environment variable. This allows it to dynamically determine and replicate the agent's permission flags in child sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a potential attack surface by interpolating user-provided topics into shell-executed strings for worktree naming and terminal labeling. The skill provides clear sanitization rules to mitigate this risk, but the underlying mechanism involves executing code based on untrusted input.
  • Ingestion points: The $target argument and the conversation history used to generate handoff summaries.
  • Boundary markers: The skill packages context into separate markdown files and launches new agent sessions with explicit opening prompts.
  • Capability inventory: Extensive use of cmux subcommands, git commands, and standard POSIX shell tools for string manipulation and process management.
  • Sanitization: The agent is explicitly instructed to enforce a strict character set ([a-z0-9-]) for slugs and to avoid shell metacharacters in labels and prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 02:22 PM
Security Audit — agent-trust-hub — handoff-to-worktree