tw-edu-pbl-designer

Pass

Audited by Gen Agent Trust Hub on May 4, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to run a local Python script (scripts/generate_pbl.py) that processes user-supplied parameters to create a PBL teaching plan in .docx format. The script uses a local utility library for document styling.
  • [EXTERNAL_DOWNLOADS]: The instructions describe the use of platform-native Model Context Protocol (MCP) connectors for tasks like searching curriculum data or uploading files to Google Drive. These are standard platform features that require user configuration and are governed by the platform's security model.
  • [SAFE]: The skill references shared configuration and strategy files located in parent directories (e.g., ../../tw_edu_concept_alignment.md). These files are part of the author's (FW1201) integrated ecosystem for educational tools and represent legitimate shared resources.
  • [DATA_EXFILTRATION]: While the skill mentions uploading to Google Drive, it includes a strict safety directive requiring the agent to display a confirmation summary and wait for explicit user approval before any write or upload operations occur.
Audit Metadata
Risk Level
SAFE
Analyzed
May 4, 2026, 12:34 AM