handoff-to-worktree
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing shell commands via
cmuxandgitto manage development workspaces and repository worktrees. It constructs strings to launch freshclaudeinstances with specific instructions. - [DYNAMIC_EXECUTION]: The skill uses shell utilities to decode the
CMUX_AGENT_LAUNCH_ARGV_B64environment variable. This allows it to dynamically determine and replicate the agent's permission flags in child sessions. - [INDIRECT_PROMPT_INJECTION]: The skill creates a potential attack surface by interpolating user-provided topics into shell-executed strings for worktree naming and terminal labeling. The skill provides clear sanitization rules to mitigate this risk, but the underlying mechanism involves executing code based on untrusted input.
- Ingestion points: The
$targetargument and the conversation history used to generate handoff summaries. - Boundary markers: The skill packages context into separate markdown files and launches new agent sessions with explicit opening prompts.
- Capability inventory: Extensive use of
cmuxsubcommands,gitcommands, and standard POSIX shell tools for string manipulation and process management. - Sanitization: The agent is explicitly instructed to enforce a strict character set (
[a-z0-9-]) for slugs and to avoid shell metacharacters in labels and prompts.
Audit Metadata