Back to skill

Security audit

Training Certificate Mgmt

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plain-text certificate-management workflow that openly handles trainee certificate data, with no executable code or hidden install behavior.

Before using this skill with real trainees, limit inputs to necessary certificate fields, mask ID numbers where possible, restrict access to certificate records and verification links, and define retention/deletion rules outside the skill.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly processes highly sensitive personal data such as names, national ID/student numbers, training records, scores, delivery tracking, and signoff information, but it provides no privacy notice, minimization guidance, retention limits, access control expectations, or masking requirements. In a certificate-management workflow, this omission can lead downstream agents or operators to collect, expose, retain, or distribute personally identifiable information more broadly than necessary.

Static analysis

No suspicious patterns detected.