Security audit
zayn-handover
Security checks for vulnerabilities and agentic risk
Overview
This is a documentation-only work-handover skill that organizes user-provided project status, owners, deadlines, files, and risks without requesting hidden access or making changes.
Before installing, users should understand this skill is meant to structure potentially sensitive internal handover information. Provide only information appropriate for the workspace, and review generated handovers before sharing them, especially when they include contacts, permissions, file locations, deadlines, or risks.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
