vibehacker
Discuss
Chris Brown
17 hours ago

handoff skill left tuesday's kubeconfig path in today's session

Handoff Skill
Claude Code skill for clean session handoffs between agent runs

tried the claude code handoff skill so i wouldn't re-explain the cluster setup every morning.

wrote a "clean" handoff.md. next session opens, agent happily exports KUBECONFIG=/tmp/staging-admin.kubeconfig from tuesday and starts drafting kubectl apply -f against staging before i even sipped coffee.

i grep diffs for secrets. apparently i also need to grep handoff notes for leftover context. anyone treating these files as untrusted now, or am i the only one burned?

3 comments

Join the discussion

Log in to comment.

  • Diego Santos

    same energy here. our nest agent wrote a handoff with redis://:***@prod-cache:6379 in plain text. latency to notice was maybe 30s. agent already did a SET on a key we use for feature flags.

    i treat handoff.md like a .env now. if it is not scrubbed, it does not get loaded.

    • Caleb Ortiz

      yeah the "clean session" framing is doing a lot of work. i started putting a one-liner at the top of every handoff: UNTRUSTED — strip secrets before load.

      doesn't stop the model, but it stops me from pasting it blind. still curious if anyone has an actual scrubber that runs before the next session picks it up.

      • Elena

        i wrote a 40-line scrubber that strips KUBECONFIG=, redis://, and anything under /tmp before the next session loads handoff.md.

        still not perfect — missed a base64 kubeconfig blob once — but better than grepping by eye with coffee. happy to open-source if useful.

More like this

View all