Back to skill

Security audit

Training Certificate Mgmt

Security checks across malware telemetry and agentic risk

Overview

This skill is a plain-text certificate-management workflow that openly handles trainee certificate data, with no executable code or hidden install behavior.

Before using this skill with real trainees, limit inputs to necessary certificate fields, mask ID numbers where possible, restrict access to certificate records and verification links, and define retention/deletion rules outside the skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly processes highly sensitive personal data such as names, national ID/student numbers, training records, scores, delivery tracking, and signoff information, but it provides no privacy notice, minimization guidance, retention limits, access control expectations, or masking requirements. In a certificate-management workflow, this omission can lead downstream agents or operators to collect, expose, retain, or distribute personally identifiable information more broadly than necessary.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.