Back to skill

Security audit

Education

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only education skill with disclosed, purpose-aligned features, but student analytics and auto-grading need careful human oversight.

Install only if you can govern student data appropriately. Use consent, access controls, retention limits, and human review for auto-grading, engagement scores, and at-risk labels; do not rely on automated outputs as the sole basis for academic, disciplinary, or support decisions. Review any suggested swarm or memory-sharing companion skills separately before installing them.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill advertises student analytics, engagement scoring, at-risk identification, and automated assessment, but provides no user-facing warning about handling sensitive student data or the consequences of automated educational decisions. In an education context, these features can influence student outcomes and involve FERPA-regulated information, so omission of clear cautions and governance guidance increases the risk of privacy misuse, overcollection, and unfair reliance on automated scoring or risk labeling.

Static analysis

No suspicious patterns detected.