mindtickle-security-basics

v2026.09.24

Threat-model and harden a Mindtickle tenant and its identity, connector, API, content, and reporting integrations. Use when conducting security review or control remediation. Trigger with "secure Mindtickle integration".

GitHub
安装命令
npx skhub add jeremylongshore/mindtickle-security-basics
Markdown
SKILL.md

Mindtickle Security and Privacy Control Review

Overview

Translate shared responsibility into testable controls for identities, tenant boundaries, employee data, content, integrations, evidence, and incident response.

Prerequisites

  • A scoped architecture, data inventory, identity model, contract registry, and accountable owners
  • Current customer policy, threat model, retention schedule, and incident process
  • Authorized access to Mindtickle trust artifacts and tenant-specific security documentation

Tool Discipline

Use Read, Glob, and Grep to inspect configuration and evidence, WebFetch for current official security material, and Write or Edit for the threat model, control matrix, and sanitized findings.

Current Contract

Mindtickle describes role-based access, customer responsibility for SSO, roles, provisioning, and data lifecycle, plus independent compliance and security assessments. Certifications inform assurance but do not replace customer control validation.

Authentication

Separate users, administrators, provisioning identities, managed connectors, API principals, and support access. Require least privilege, phishing-resistant identity controls where available, rotation, revocation, access review, and no shared credentials.

Instructions

  1. Inventory tenants, environments, principals, roles, integrations, data classes, content audiences, exports, caches, logs, and support paths.
  2. Map threats across account takeover, overprivilege, tenant misrouting, lifecycle drift, data leakage, malicious content, replay, schema injection, and compromised dependencies.
  3. Verify SSO enforcement, identity-provider MFA, provisioning ownership, disabled-user handling, administrator separation, and periodic access review.
  4. Test tenant binding, input and output validation, secret handling, egress restrictions, encryption, logging redaction, and evidence integrity.
  5. Review data minimization, retention, deletion, exports, residency commitments, learner transparency, and restricted assessment or coaching data.
  6. Validate connector and adapter scopes, contract provenance, dependency controls, incident contacts, support disclosure, and credential compromise response.
  7. Rank findings by exploitable path and business impact; assign owner, remediation, verification, and due date.
  8. Re-test changed controls and preserve redacted evidence rather than closing on configuration screenshots alone.

Approval Boundaries

Do not weaken SSO, grant roles, rotate production credentials, access learner records, change retention, or conduct intrusive testing without explicit authorization.

Output

Return the asset and data inventory, trust boundaries, threat model, control evidence, findings, owners, remediation dates, residual risks, and re-test results.

Error Handling

ConditionResponse
A secret appears in evidenceRestrict access, remove it, rotate as required, and regenerate the artifact.
Tenant-specific assurance is unavailableRecord the gap and request it through the authorized trust or commercial channel.
A critical control failsStop affected integration activity and invoke the incident process.

Example

scope=reporting-adapter; principals=3-owned; tenant-binding=pass; pii-logs=none; findings=1-high,2-medium; retest=scheduled

Resources

Next Steps

Track remediation to evidence-backed closure and schedule the next access and contract review.

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

2026年9月24日

分类

未分类

许可证

MIT

源路径

skills/.curated/mindtickle-security-basics

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8