Back to skill

Security audit

training-course-designer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent training-material generator with some review and privacy caveats, but no hidden execution, persistence, credential use, or exfiltration behavior was found.

Install only if you want an agent to help draft corporate training packages. Treat all generated materials as drafts: review for factual accuracy, legal/compliance fit, accessibility, bias, and company policy before sending to employees. Use placeholders or sanitized examples instead of personal employee data, confidential HR records, customer information, internal recordings, or sensitive workplace messages.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
1.  **Course Outline Document**: The master document detailing the course background, audience, objectives, schedule, and module-by-module content breakdown.
2.  **Instructor Guide**: A detailed guide for the facilitator, including talking points, activity instructions, time cues, and materials checklist.
3.  **Participant Handbook**: A workbook for learners, including key concepts, space for notes, exercise worksheets, and reference materials.
4.  **Interactive Activity Sheets**: Ready-to-print instruction sheets for each major interactive activity.
5.  **Evaluation & Follow-up Plan**: A plan that includes a post-training evaluation survey (Kirkpatrick Level 1 & 2) and a template for a 30-day follow-up to assess on-the-job application (Level 3).

## Reference Documents & Templates

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README repeatedly markets 'ONE-CLICK generation' of 'ready-to-use' training packages, assessments, and communications, but does not place a prominent warning near the claim that outputs must be reviewed before operational deployment. This creates a realistic risk that inaccurate, inappropriate, biased, or non-compliant content will be sent to employees or used in training without validation, especially because the package includes assessment and communication materials.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README tells the agent/user to 'Ask Manus to generate the complete package,' which is a broad invocation pattern with little constraint on scope, review gates, or approved use boundaries. In a skill that produces operational training, assessments, and outbound communications, vague trigger guidance can encourage overbroad automation and generation of content that is used without sufficient human validation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description uses very broad activation language ('Use when designing training courses, workshops, or learning programs'), which can cause the skill to be invoked for a wide range of ordinary requests without clear gating. Over-broad triggering increases the chance the agent applies heavyweight behaviors or file-generating workflows in contexts where the user did not explicitly request them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The one-click workflow instructs automatic generation and organization of 14 documents into a folder structure, but it does not require warning, consent, or safeguards around multi-file creation or overwriting existing materials. In an agent environment with filesystem or workspace write capabilities, this can lead to unexpected bulk file creation, clobbering of existing content, or noisy side effects from a loosely scoped user request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions in Chinese only, with no user opt-in, alternative language, or justification that the content is intentionally restricted to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide encourages users to generate participant-facing emails, assessments, surveys, and follow-up materials, but it does not instruct them to avoid pasting personal employee data, confidential company details, or regulated information into prompts. In an HR/L&D context, users may naturally include names, performance issues, internal policies, or sensitive organizational details, creating unnecessary data exposure through the AI workflow.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · templates/instructor-guide-template.md (reported line 30)May include surrounding context.

md
## 3. Detailed Time Schedule & Facilitation Notes

| Time        | Duration | Module                | Activity                                       | Facilitation Notes                                                                                                                              |
|-------------|----------|-----------------------|------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------|
| 09:00-09:15 | 15 min   | Opening               | Welcome, Agenda, Icebreaker                    | - Welcome participants. <br>- Briefly review the agenda. <br>- Lead the icebreaker activity with energy.                                          |
| 09:15-10:30 | 75 min   | Module 1: [Title]     | Lecture & Case Study Discussion                | - Present the core concepts. <br>- Divide participants into groups for the case study. <br>- Facilitate a debrief, highlighting key insights.      |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · templates/instructor-guide-template.md (reported line 34)May include surrounding context.

md
|-------------|----------|-----------------------|------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------|
| 09:00-09:15 | 15 min   | Opening               | Welcome, Agenda, Icebreaker                    | - Welcome participants. <br>- Briefly review the agenda. <br>- Lead the icebreaker activity with energy.                                          |
| 09:15-10:30 | 75 min   | Module 1: [Title]     | Lecture & Case Study Discussion                | - Present the core concepts. <br>- Divide participants into groups for the case study. <br>- Facilitate a debrief, highlighting key insights.      |
| 10:30-10:45 | 15 min   | Break                 |                                                |                                                                                                                                                 |
| ...         | ...      | ...                   | ...                                            | ...                                                                                                                                             |

## 4. Module-by-Module Guide

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · templates/instructor-guide-template.md (reported line 35)May include surrounding context.

md
| 09:00-09:15 | 15 min   | Opening               | Welcome, Agenda, Icebreaker                    | - Welcome participants. <br>- Briefly review the agenda. <br>- Lead the icebreaker activity with energy.                                          |
| 09:15-10:30 | 75 min   | Module 1: [Title]     | Lecture & Case Study Discussion                | - Present the core concepts. <br>- Divide participants into groups for the case study. <br>- Facilitate a debrief, highlighting key insights.      |
| 10:30-10:45 | 15 min   | Break                 |                                                |                                                                                                                                                 |
| ...         | ...      | ...                   | ...                                            | ...                                                                                                                                             |

## 4. Module-by-Module Guide

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The pre-training reminder template asks participants to share survey responses, communication challenges, meeting recordings, and example emails/messages, but provides no guidance on minimizing sensitive content, obtaining consent, or handling confidential business data. In a corporate L&D context, those artifacts can easily contain personal data, internal communications, customer information, or proprietary material, creating unnecessary privacy and confidentiality exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

该技能文件从标题到正文全部以中文呈现,未见任何允许用户选择其他语言、双语支持或说明为何必须使用中文的自然语言声明。根据规则,强制单一语言而没有用户选择或明确、合理的地域性说明,可构成自然语言政策违规。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The welcome message encourages participants to disclose their location and biggest communication challenge in a group setting without an opt-out or privacy cue. While low severity, this can pressure attendees to reveal personal or sensitive workplace context to peers, especially in recorded or cross-functional sessions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.