The skill implements a persistent cross-session state injection mechanism that allows malicious instructions to compromise future, unrelated user sessions.
npx skills add https://github.com/xoonjaeho/claude-skill-handoffSkill name or description references a well-known AI brand, which may suggest impersonation.
claude
The skill instructs the agent to write state to a file that is automatically re-injected into future sessions via a 'SessionStart hook'. This creates a mechanism for cross-session state persistence that could be exploited to inject instructions into new, unrelated sessions. [ensemble: confirmed by 3/3 passes; severity set to the agreed median (ADR-0067).]
a SessionStart hook (if installed) re-injects it into the new context and archives it.
Skill body contains no code blocks or usage examples, making it harder for users to evaluate.
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/xoonjaeho/claude-skill-handoff)<a href="https://mondoo.com/ai-agent-security/skills/github/xoonjaeho/claude-skill-handoff"><img src="https://mondoo.com/ai-agent-security/api/badge/github/xoonjaeho/claude-skill-handoff.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/xoonjaeho/claude-skill-handoff.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.