Agent skill

Ripwire Subsystem Handoff

by redhat-et in redhat-et/ripwire

Produces a short brief for handing a code subsystem to a teammate or fresh session, using ripwire to rank symbols, expand bodies and surface design docs.

Apache-2.0Auto-check: notesAgent Workflows

Install Ripwire Subsystem Handoff

skills CLI
$ npx skills add redhat-et/ripwire --skill ripwire-handoff -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install redhat-et/ripwire ripwire-handoff --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/redhat-et/ripwire.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ripwire-handoff .claude/skills/ripwire-handoff && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ripwire-handoff
GitHub stars
2.4k
Token cost
~1.8k tokens
SKILL.md length
947 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Apache-2.0

At a glance

Produces a short brief for handing a code subsystem to a teammate or fresh session, using ripwire to rank symbols, expand bodies and surface design docs.

  • Works in 4 steps: Task-relevant symbols — ripwire… → Expand the key symbols — ripwire… → Design rationale — ripwire… → …
  • Handing an area of the codebase to a new teammate or successor
  • SKILL.md covers Calibration — what's fact vs…, Stamp the commit you measured…, Output and Mid-task session handoff —…
  • Calls git

What it does

Handing a subsystem to a teammate, a successor or a fresh session takes four steps with the ripwire CLI and produces a compact brief that can be pasted, rather than a pile of source. First it ranks the symbols most relevant to the subsystem with --for and --top-k, noting file paths, complexity and reuse counts; the top ten are what the recipient most needs.

Next it expands the top three symbols with --expand to get full bodies and callee signatures, which go into the brief verbatim. Bodies are redacted by default, so credentials such as API keys and tokens are masked unless you deliberately pass --no-redact. Then --recall pulls the relevant design and planning docs so the brief can say why the design is what it is, and --notes surfaces gotchas earlier agents pinned, with --note-add for leaving new ones.

A fourth step points --hotspots at the subsystem to describe maintenance and bus-factor risk; the supplied text stops before those details. Neighboring skills cover other needs: ripwire-orient for understanding the area yourself, ripwire-navigate for one symbol's contract and ripwire-layers for an architecture read.

When your agent uses it

  • Handing an area of the codebase to a new teammate or successor
  • Preparing a brief for a fresh agent session that continues the work
  • Writing up why a subsystem was designed the way it was

Example prompts

  • “Write a handoff brief for the ingest pipeline for the engineer taking it over.”
  • “Brief a new session on the MCP server loop, with the key entry points and design docs.”
  • “I am leaving this project. Prepare a handoff for the graph ranking subsystem, including known gotchas.”

Requirements

  • The ripwire command-line tool
  • Shell access to run it from the repository root
  • Pre-approved tools (allowed-tools): Bash, Read

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Task-relevant symbols — ripwire --for="SUBSYSTEM" --top-k=20
  2. Expand the key symbols — ripwire --expand=SYM1,SYM2,SYM3 --legend=compact
  3. Design rationale — ripwire --recall="SUBSYSTEM"
  4. Maintenance risk, scoped to the subsystem — point --hotspots straight at the subsystem instead of

What it can do on your machine

Read from SKILL.md and the folder at commit 60dd3b3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ripwire Subsystem Handoff loads about 1.8k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 947 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from redhat-et/ripwire at commit 60dd3b3, republished under its Apache-2.0 licence (© redhat-et). 947 words, ~1,773 tokens.

Download SKILL.mdSave it as .claude/skills/ripwire-handoff/SKILL.md (or your agent's skills folder).
name
ripwire-handoff
description
Brief someone ELSE on a subsystem — 'hand this area off' to a successor, teammate or fresh session: purpose, the 2-3 entry points with bodies, the design docs that say WHY, hotspot/bus-factor risk — a compact pasteable brief, not a wall of source. Understanding it yourself → orient.
allowed-tools
Bash, Read

Handoff with ripwire

Nearest neighbours: • You need to UNDERSTAND the subsystem yourself first (not brief someone else) → ripwire-orient. • You need ONE symbol's full contract, not a whole-subsystem brief → ripwire-navigate (--expand). • The recipient needs an architecture/layering read specifically → ripwire-layers.

Trigger: you're handing a subsystem to another agent or developer and want to give them a fast, accurate brief — not a wall of source code.

<dir> = repo root. SUBSYSTEM = the area in plain words (e.g. "ingest pipeline", "graph ranking", "MCP server loop").

  1. Task-relevant symbols — ripwire <dir> --for="SUBSYSTEM" --top-k=20 Output: <sigs> ranked by relevance. The top 10 are the symbols the recipient most needs to know. Note their file paths, complexity (cx=), and reuse count (in=).

  2. Expand the key symbols — ripwire <dir> --expand=SYM1,SYM2,SYM3 --legend=compact (Pick the top 3 by rank from step 1.) Output: full bodies + callee signatures. This is the actual contract — paste it into the handoff verbatim rather than paraphrasing. Bodies are redacted by default — high-confidence credentials (API keys, tokens, connection strings) are masked before you see them, so pasting this straight into a handoff doc is safe as-is; pass --no-redact only if you deliberately need the verbatim secret (e.g. auditing the credential-handling code itself).

  3. Design rationale — ripwire <dir> --recall="SUBSYSTEM" Output: most relevant markdown docs (planning/design notes, READMEs) in full. Read and summarize the key decisions — why this design, not another. That's what the recipient most needs and least gets from reading code. Also check ripwire <dir> --notes --legend=compact for this subsystem's symbols/files — any gotcha a prior agent already pinned (<note d="date">…</note>) surfaces automatically on the symbols step 1/2 emit; fold it into the brief instead of letting the recipient rediscover it. Before you hand off, --note-add="SYM_or_path: text" any trap you found yourself that isn't already written down — the cheapest thing you can leave the successor. If the same symbol has collected several notes across handoffs, that's a signal to graduate it out of prose entirely, into a --quality-ack reason or a standing --arch deny rule.

  4. Maintenance risk, scoped to the subsystem — point --hotspots straight at the subsystem instead of filtering the whole-repo list: ripwire <subdir> --hotspots (verified: subdir scoping works, same as --dead-code=DIR). If the subsystem isn't a clean subdirectory, keep the repo root and --exclude the rest (repeatable flag) to fence the scan to just the area you're briefing on. Also worth a look: ripwire <dir> --hotspots --legend=compact (whole-repo, no scoping) to see whether any subsystem file also lands in the global top-10 — a file can be locally worst-in-subsystem and still unremarkable repo-wide, or vice versa; that distinction matters to the recipient. Tell them: "this file is gnarly — high churn, high complexity — be careful and run tests after any change here."

Calibration — what's fact vs framing here

  • Steps 1–3 are direct reads (ranked signatures, full bodies, doc text) — trustworthy as far as the underlying call graph goes (name-based edges; a symbol with high amb= in --expand's <calls> block means some of ITS calls were ambiguous — don't present those as certain in the brief, flag them). --recall returns doc text, not a verified fact — summarize what the docs claim, not what's provably still true; a stale design doc will still get picked up.
  • Step 4 (hotspots) is churn × cognitive complexity — a maintenance-pain signal, not a defect count. Frame it to the recipient as "developers keep touching this, tread carefully," not "this file has bugs."
Show full SKILL.md (389 more words)Show less

Stamp the commit you measured at — at="<sha>[+dirty]"

A brief is read hours or days later, against a HEAD that has moved. Every number you quote must carry the commit it was measured at, or the recipient cannot tell a stale finding from a live one.

Several repo-reading verbs now do this for you: the header carries at="<sha>", and at="<sha>+dirty" when the working tree had uncommitted changes at measure time. Real output from this repo:

<quality-delta baseline="git-HEAD" regressions="0" … gating="0" at="f0a45e43d">

+dirty is the important half. A stamp ending in +dirty means the numbers describe a working tree that exists on exactly one machine and is not recoverable from the sha — it is not reproducible by the recipient. Either commit first and re-measure, or say so explicitly in the brief.

What actually carries a stamp today (verified by running each verb — do not assume it is universal):

verbstamp
--quality-delta · --pr-context · --test-gate · --map-diff · --doc-driftat="<sha>[+dirty]"
--stray-contenthead="<sha>" — different attribute name, and no +dirty suffix
--situ · --cochange · --ownersnone — record the sha yourself (git rev-parse --short HEAD)

Two traps: the attribute is head= rather than at= on --stray-content, so a script grepping only for at= silently gets nothing; and in --doc-drift the name at= is overloaded — the header at= is a git sha, but each drift ROW's at= is a file path (at="src/mcp.h"). Anchor on the header, not the first match.

Output

Handoff brief: (1) what the subsystem does in 2 sentences, (2) the 3 key entry-point symbols with file:line and their signatures (from --expand), (3) the design decisions the recipient must know (from --recall), (4) any hotspot files to be careful with, flagged if churn/complexity data looks stale (no git history, non-git root). Aim for under 600 tokens.

Mid-task session handoff — --handoff

Handing off an INTERRUPTED WORKING SESSION (not a subsystem summary)? ripwire <dir> --handoff --legend=compact emits the whole continuation packet in one deterministic call: a <verified> section (branch, HEAD sha with +dirty marker, changed files + their symbols, transitive blast-radius size, tests-to-run) that is pure disk truth, and a <heuristic> section (co-change partners not in the diff, committed --note-add notes on the touched files, plan/design doc pointers ranked by a branch+commit-subject query) that is labeled suggestion, never presented as fact. Composes with --token-budget=N — heuristic rows drop tail-first and the header discloses withheld=; verified rows never drop. Single-root only; paste the packet to the next agent as-is.

© redhat-et, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ripwire-handoff of redhat-et/ripwire.

Open the folder on GitHubat commit 60dd3b3

Compare with similar skills

Ripwire Subsystem Handoff next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ripwire Subsystem Handoff compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ripwire Subsystem Handoff this skillredhat-et/ripwire2.4k—~1.8kAutomated safety check: NotesApache-2.0
CodemapJordanCoin/codemap704—~1.8kAutomated safety check: PassMIT
ccc Semantic Code Searchcocoindex-io/cocoindex-code2.8k—~938Automated safety check: PassApache-2.0
Repomix Codebase Packeryamadashy/repomix29k—~1.3kAutomated safety check: NotesMIT
Codebase Handbook BuilderRuhan-Wang/Harness_Handbook333—~2.2kAutomated safety check: PassApache-2.0
Codebase SearchHelweg/open-codebase-index216—~1.3kAutomated safety check: PassMIT

Similar skills

  • Codemap

    JordanCoin/codemap

    Gives an agent a quick map of a codebase's structure, dependencies, changes and handoffs, and tunes per-project config so the output stays code-first.

    704 GitHub stars~1.8k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed
  • ccc Semantic Code Search

    cocoindex-io/cocoindex-code

    Semantic code search and index management with the ccc CLI: the agent initializes, indexes and queries the project by concept, filtering by language or path.

    2.8k GitHub stars~938 tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Repomix Codebase Packer

    yamadashy/repomix

    Packs a local directory or remote GitHub repository into one AI-friendly file with Repomix, then searches it to explore structure, find patterns and count tokens.

    29k GitHub stars~1.3k tokensUpdated 5 days ago
    Agent WorkflowsAuto-check: notes
  • Codebase Handbook Builder

    Ruhan-Wang/Harness_Handbook

    Generates, refreshes, validates and uses a compact handbook that maps where a change touches in a repository, using the active Codex session and no external LLM API.

    333 GitHub stars~2.2k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • Codebase Search

    Helweg/open-codebase-index

    Chooses the right retrieval tool for code questions: compact context for unfamiliar repos, direct lookup for known symbols, call graphs for relationships and grep for exhaustive matches.

    216 GitHub stars~1.3k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Codebase Search Workflow

    Helweg/open-codebase-index

    Directs an agent to use a local codebase index for repository orientation, definition lookups, call graphs and semantic search before turning to web lookups.

    216 GitHub stars~822 tokensUpdated today
    Agent WorkflowsAuto-check passed

More from redhat-et/ripwire

All 19 skills in this repo
  • Ripwire Output Emission

    redhat-et/ripwire

    Rules for writing and converting formatted output in ripwire's C++ source with its emit helpers, keeping every printed byte identical to the old printf output.

    2.4k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Ripwire Change Check

    redhat-et/ripwire

    Checks whether a working-tree diff or a pull request is safe to merge: blast radius, tests to run, contract breaks, branch conflicts and stranded work.

    2.4k GitHub stars~4.3k tokensUpdated today
    Auto-check: notes
  • Ripwire Graph Query

    redhat-et/ripwire

    Answers call-graph questions that combine several conditions, such as complex functions that reach a target or untested symbols near main, using ripwire's graph-query mode.

    2.4k GitHub stars~1.1k tokensUpdated today
    Auto-check: notes
  • Ripwire Code Navigation

    redhat-et/ripwire

    Answers questions about a named symbol, such as its callers, what it calls, the path between two symbols or the downstream impact of changing it, using the ripwire CLI.

    2.4k GitHub stars~4.8k tokensUpdated today
    Auto-check: notes
  • Contributor guide for reading clang optimization remarks while editing ripwire's own C++, deciding between a source change and a build change such as LTO or PGO.

    2.4k GitHub stars~3.1k tokensUpdated today
    Auto-check: notes
  • Maps an unfamiliar repo or subsystem with the ripwire CLI before reading files, climbing an escalation ladder only until you are oriented.

    2.4k GitHub stars~4.5k tokensUpdated today
    Auto-check: notes

Questions about Ripwire Subsystem Handoff

What does Ripwire Subsystem Handoff do?

Produces a short brief for handing a code subsystem to a teammate or fresh session, using ripwire to rank symbols, expand bodies and surface design docs. Handing a subsystem to a teammate, a successor or a fresh session takes four steps with the ripwire CLI and produces a compact brief that can be pasted, rather than a pile of source. First it ranks the symbols most relevant to the subsystem with --for and --top-k, noting file paths, complexity and reuse counts; the top ten are what the recipient most needs.

When should I use Ripwire Subsystem Handoff?

Ripwire Subsystem Handoff fits situations like: handing an area of the codebase to a new teammate or successor; preparing a brief for a fresh agent session that continues the work; writing up why a subsystem was designed the way it was.

How do I install Ripwire Subsystem Handoff in Claude Code?

Run `npx skills add redhat-et/ripwire --skill ripwire-handoff -a claude-code`. Or copy the skill folder (skills/ripwire-handoff in redhat-et/ripwire) into .claude/skills/ripwire-handoff in your project. Claude Code loads it when a task matches its description.

How do I install Ripwire Subsystem Handoff in Codex?

Run `npx skills add redhat-et/ripwire --skill ripwire-handoff -a codex`. Or copy the skill folder (skills/ripwire-handoff in redhat-et/ripwire) into .agents/skills/ripwire-handoff in your project. Codex loads it when a task matches its description.

Can I use Ripwire Subsystem Handoff in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add redhat-et/ripwire --skill ripwire-handoff -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ripwire-handoff, .gemini/skills/ripwire-handoff, .github/skills/ripwire-handoff and .opencode/skills/ripwire-handoff in your project.

What does Ripwire Subsystem Handoff need to run?

Going by SKILL.md and its folder, Ripwire Subsystem Handoff needs the command-line tools its instructions call (git). Our summary lists: The ripwire command-line tool; Shell access to run it from the repository root. Its frontmatter pre-approves these tools: Bash, Read.

Does Ripwire Subsystem Handoff access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ripwire Subsystem Handoff safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ripwire Subsystem Handoff use?

Ripwire Subsystem Handoff is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ripwire Subsystem Handoff use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ripwire Subsystem Handoff?

Skills that share tags, products or a category with Ripwire Subsystem Handoff: Codemap (JordanCoin/codemap, 704 stars), ccc Semantic Code Search (cocoindex-io/cocoindex-code, 2.8k stars), Repomix Codebase Packer (yamadashy/repomix, 29k stars) and Codebase Handbook Builder (Ruhan-Wang/Harness_Handbook, 333 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ripwire Subsystem Handoff?

redhat-et (a GitHub organization) maintains it in redhat-et/ripwire, which has 2,428 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.

Source: redhat-et/ripwire on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.