Back to skill

Security audit

Liberating Structures

Security checks for vulnerabilities and agentic risk

Overview

This is a knowledge-only facilitation skill with no executable code or system access, though users should apply consent and privacy judgment when using its recording-related workshop advice.

Install risk is low because this is a static knowledge skill. When using its workshop guidance, especially any advice to photograph, video, or record participant outputs, get explicit participant consent, explain how recordings will be used and retained, and offer a non-recorded option.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The file explicitly suggests recording participants' drawings with cameras and video recorders without mentioning informed consent, privacy expectations, retention, or handling of sensitive disclosures. In this facilitation context, drawings may surface emotions, interpersonal dynamics, or hidden knowledge, so recording can capture sensitive personal information and create privacy, legal, and trust harms if done without safeguards.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
references/structures/12-12-2510-crowd-sourcing.yaml:36