Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add nathanonn/agent-skills --skill handoff-docgit clone --depth 1 https://github.com/nathanonn/agent-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/nathanonn/agent-skills/handoff-doc)<a href="https://agentmods.dev/skills/nathanonn/agent-skills/handoff-doc"><img src="https://agentmods.dev/badge/skills/nathanonn/agent-skills/handoff-doc/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/nathanonn/agent-skills/handoff-doc"><img src="https://agentmods.dev/badge/skills/nathanonn/agent-skills/handoff-doc.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Rogue Agent · line 93 Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.Fix: Prevent the skill from modifying its own code, SKILL.md, or configuration files. Treat skill files as read-only at runtime.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00136 | $0.01169 |
| Opus 5 | $0.00068 | $0.00584 |
| Sonnet 5 | $0.00027 | $0.00234 |
| Haiku 4.5 | $0.00014 | $0.00117 |
Grade A, and why
handoff-doc scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 106 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Handoff Doc
Write a concise handoff doc that captures the current session's work so a future session can pick up cold. The whole point is leverage: instead of the next session re-reading a long transcript, it reads one tight doc and knows what was done, where things live, what's verified, and what's still open.
The user gives you a destination path. You supply the content by distilling what actually happened in this session. Keep it concise — a handoff is a launch pad, not a transcript.
Workflow
1. Resolve the target path
Look at the path the user gave and the folder it lives in.
- List sibling files in the target directory. Many handoff folders use a
YYYYMMDD_NN_short-slug.mdconvention (date, then a two-digit sequence). If the siblings follow a pattern, match it — continue the numbering and use today's date. - Sanity-check the filename against today's date. If the date in the
filename looks wrong (e.g. a year or month that doesn't match today, or it's
out of order with its siblings), it's probably a typo. Surface it with
AskUserQuestionand offer the corrected name — never silently rename.
2. Decide create vs. update
-
If the target doesn't exist (or is an empty placeholder), create it.
-
If the target already exists with content, don't assume. Use
AskUserQuestionto ask how to proceed, with these options:- Overwrite in place (replace the contents).
- Append a new dated section to the same file.
- Sequel — write a new file at the next
_NN_in the series, referencing the prior one.
This is a genuine fork with no safe default — losing a handoff someone wanted kept is worse than asking one question.
3. Distill the session into the doc
Read back over what happened this session and pull out what the next session actually needs. Default audience is a future Claude session, and default scope is as-built state plus open follow-ups — these fit most cases, so just proceed with them unless the conversation makes the audience or scope genuinely ambiguous (then ask).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 106 lines · 136 tokens per session scan A aac719251eec
handoff-doc is a skill published in the GitHub repository nathanonn/agent-skills (19 stars, last pushed 21d ago), licensed MIT. It adds 136 tokens to every session and 1,169 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
media-ingest
Ingest video, audio, PDF, book, screenshot, and GitHub repo content into the brain. Multi-format handling with entity extraction and backlink propagation. Covers video-ingest, youtube-ingest, and book-ingest subtypes.
mem0-oss-to-platform
Plan and then execute a migration of a project from the mem0 open-source / self-hosted SDK (the local Memory class) to the mem0 Platform / hosted / managed SDK (the MemoryClient class). Use this whenever a developer wants to move, switch, or migrate their mem0 usage off OSS/self-hosted to the hosted API — e.g.…
Cortex
Operate Cortex, the LifeOS memory system — the typed Knowledge Archive (People, Companies, Ideas, Research with typed related: links) plus recall of prior work sessions, ISAs, and conversations. Search, add, harvest, develop, ingest, distill, graph-navigate, recall. USE WHEN cortex, knowledge, knowledge base, search…
memory
Use when the user asks to remember, recall, forget, update, search, or inspect durable OpenSquilla memory, including profile facts in USER.md and long-term notes in MEMORY.md or memory//.md.
ha-data-stores
Map of Hope Agent's local data stores and safe read-only query workflow. Use when the user asks where Hope Agent stores data, wants to inspect sessions/messages/memory/logs/background jobs/knowledge indexes/settings, asks the model to query local app data, or debugging requires checking persisted state. Trigger…
establishing-project-context
Use when the user asks to establish shared project language, or project work exposes a conflicting, renamed, or deprecated domain term that needs active semantic modeling. Routine small tasks stay on the fast path.