handoff
Facilitates end-of-session rituals by capturing decisions, lessons, and open threads, creating a narrative session log for future reference.
Install this skill
Security score
The handoff skill was audited on May 29, 2026 and we found 19 security issues across 2 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
Template literal with variable interpolation in command context
| 26 | ``` |
Access to hidden dotfiles in home directory
| 5 | threads. Writes a narrative session log to ~/.origin/sessions/ and stores |
Access to hidden dotfiles in home directory
| 16 | 2. **Session log md** — narrative thread at `~/.origin/sessions/<YYYY-MM-DD-HHmm>-<slug>.md`. |
Access to hidden dotfiles in home directory
| 17 | 3. **Project status md + json** — current goals + last-handoff timestamp at `~/.origin/sessions/_status/`. |
Access to hidden dotfiles in home directory
| 34 | Read `~/.origin/sessions/_status/handoff-<project>.json` for `lastHandoff` |
Access to hidden dotfiles in home directory
| 132 | Bash heredoc to `~/.origin/sessions/<YYYY-MM-DD-HHmm>-<slug>.md`: |
Access to hidden dotfiles in home directory
| 163 | Overwrite `~/.origin/sessions/_status/<project>.md`: |
Access to hidden dotfiles in home directory
| 207 | Overwrite `~/.origin/sessions/_status/handoff-<project>.json`: |
Access to hidden dotfiles in home directory
| 219 | ### 8. Auto-commit ~/.origin/ |
Access to hidden dotfiles in home directory
| 223 | missing or `~/.origin/` is not a repo yet. |
Access to hidden dotfiles in home directory
| 226 | Bash: git -C ~/.origin add -A && \ |
Access to hidden dotfiles in home directory
| 227 | git -C ~/.origin -c user.name=Origin -c [email protected] \ |
Access to hidden dotfiles in home directory
| 229 | (sleep 1 && git -C ~/.origin add -A && \ |
Access to hidden dotfiles in home directory
| 230 | git -C ~/.origin -c user.name=Origin -c [email protected] \ |
Access to hidden dotfiles in home directory
| 235 | `~/.origin/` at the same moment (auto-commit from captures). One-second |
Access to hidden dotfiles in home directory
| 249 | Session: ~/.origin/sessions/<filename> |
Access to hidden dotfiles in home directory
| 250 | Status: ~/.origin/sessions/_status/<project>.md |
Access to hidden dotfiles in home directory
| 272 | - **Pages** are wiki-style syntheses written to `~/.origin/pages/` by the |
Access to hidden dotfiles in home directory
| 274 | - **Sessions** (this skill) live only at `~/.origin/sessions/`. They are |