mcpa-certification

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is configured to execute local Python scripts and unit tests to facilitate practical certification labs.
  • Evidence: The agent is instructed to run python3 <lesson-path>/code/main.py, python3 -m unittest discover -s <lesson-path>/code/tests -v, and python3 scripts/check_mcpa_wire.py in SKILL.md.
  • [EXTERNAL_DOWNLOADS]: The skill fetches certification program data, lesson content, and track configurations from the author's GitHub repository.
  • Evidence: The skill reads files from https://raw.githubusercontent.com/rohitg00/ai-engineering-from-scratch/main/ as defined in SKILL.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes certification content and quiz data from external sources, which constitutes a vulnerability surface if the content contains adversarial instructions.
  • Ingestion points: Fetches program.json, mcpa-f.json, en.md, and quiz.json from GitHub as specified in SKILL.md.
  • Boundary markers: Absent. There are no instructions for the agent to use specific delimiters or to disregard instructions found within the fetched content.
  • Capability inventory: The skill has the capability to execute shell commands via Python to run labs and validators.
  • Sanitization: Absent. The instructions do not specify any validation or filtering of the remote content before processing or interpolation into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 05:28 AM
Security Audit — agent-trust-hub — mcpa-certification