Back to skill

Security audit

Training Satisfaction

Security checks for vulnerabilities and agentic risk

Overview

This skill is a survey-management template that handles trainee contact and feedback data in a disclosed, purpose-aligned way, though users should add privacy controls before real deployment.

Before using this with real trainees, configure it so only necessary contact data is collected, survey answers are anonymous or pseudonymous where possible, reports are shared in aggregate by default, and retention, deletion, access-control, and consent rules are documented.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly uses learner names, contact details, departments, and survey response data for distribution, collection, and tracking, but provides no privacy, consent, minimization, retention, or access-control guidance. This creates a real privacy and compliance risk because operators may process personally identifiable information and potentially sensitive feedback without safeguards, increasing the chance of unauthorized disclosure, misuse, or noncompliant handling.

Static analysis

No suspicious patterns detected.