mcpa-certification
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is configured to execute local Python scripts and unit tests to facilitate practical certification labs.
- Evidence: The agent is instructed to run
python3 <lesson-path>/code/main.py,python3 -m unittest discover -s <lesson-path>/code/tests -v, andpython3 scripts/check_mcpa_wire.pyinSKILL.md. - [EXTERNAL_DOWNLOADS]: The skill fetches certification program data, lesson content, and track configurations from the author's GitHub repository.
- Evidence: The skill reads files from
https://raw.githubusercontent.com/rohitg00/ai-engineering-from-scratch/main/as defined inSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes certification content and quiz data from external sources, which constitutes a vulnerability surface if the content contains adversarial instructions.
- Ingestion points: Fetches
program.json,mcpa-f.json,en.md, andquiz.jsonfrom GitHub as specified inSKILL.md. - Boundary markers: Absent. There are no instructions for the agent to use specific delimiters or to disregard instructions found within the fetched content.
- Capability inventory: The skill has the capability to execute shell commands via Python to run labs and validators.
- Sanitization: Absent. The instructions do not specify any validation or filtering of the remote content before processing or interpolation into the agent's context.
Audit Metadata