claude-skills/.codex/skills/handoff
Claude 87fb428ead
feat(productivity): add handoff skill (Matt Pocock-inspired) with first-run setup, redaction enforcement, SessionStart auto-load
Ships the 5 must-haves for a handoff skill to fulfill its purpose:

1. SessionStart hook auto-loads the latest handoff (hooks/session_start.py).
   Wrapped in <handoff_from_previous_session> tags so the next agent reads
   it as data, not instructions. Disable per-session via HANDOFF_SESSIONSTART=0.

2. First-run setup with explicit save-location choice (no pre-selected
   default). 5 core questions: save location, retention, redaction
   strictness, git context, recommender scope. Prompt-once-then-default
   model — declined setup leaves a sentinel so the prompt never re-appears.

3. Mandatory checklist for the agent (references/handoff_prompt.md) — 7
   steps forcing topic-by-topic classification (State / Decision / drop)
   instead of free-handing prose.

4. Redaction linter (scripts/redaction_linter.py) — 17 stdlib regex
   patterns covering AWS/GitHub/OpenAI/Anthropic/Slack/Stripe keys, JWT,
   private-key blocks, env-style secret assignments, DB connection strings
   with creds, bearer tokens, URL token params, email, phone. Inline
   whitelist marker for true false positives. Strict/warn/off modes.

5. mtime-guarded cleanup (scripts/cleanup.py) — never deletes a handoff
   the user edited as a working surface.

Wrapper layout matches productivity/capture and productivity/reflect:
SKILL.md preserves Matt's seven sentences verbatim, surrounded by
invocation triggers, output path discipline, 5-section template, and an
anti-patterns block. Plus cs-handoff-author agent, /cs:handoff and
/cs:handoff-setup commands, 5 reference docs (each citing 5-6 sources),
6 stdlib-only scripts (all pass --help and --sample).

Coexists with engineering/handoff/ (code/PR-focused, no setup, no
redaction enforcement, no SessionStart hook). Both shipped in
marketplace.json. Codex slug collision: the productivity variant wins
the .codex/skills/handoff symlink because it's the more general-purpose
version; both remain in .codex/skills-index.json.

Credit to Matt Pocock surfaces in README + SKILL.md footer + scaffold
footer, not as a manifest attribution block (cleaner plugin.json).

Verified:
- All 6 Python tools pass --help and --sample
- redaction_linter --sample finds 8 planted secrets, exits 1 (strict)
- SessionStart hook smoke-tested end-to-end against a real scaffold
- check_plugin_json.py --all clean (0 failures across all plugins)
- sync-codex-skills.py re-ran clean (productivity: 4 -> 5)

https://claude.ai/code/session_01KLhHBAfEDXdQMeRe6G8sRa
2026-05-21 17:33:42 +00:00

Symbolic link
1 line
No EOL
41 B
Text

../../productivity/handoff/skills/handoff