tw-edu-pbl-designer
Pass
Audited by Gen Agent Trust Hub on May 4, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to run a local Python script (scripts/generate_pbl.py) that processes user-supplied parameters to create a PBL teaching plan in.docxformat. The script uses a local utility library for document styling. - [EXTERNAL_DOWNLOADS]: The instructions describe the use of platform-native Model Context Protocol (MCP) connectors for tasks like searching curriculum data or uploading files to Google Drive. These are standard platform features that require user configuration and are governed by the platform's security model.
- [SAFE]: The skill references shared configuration and strategy files located in parent directories (e.g.,
../../tw_edu_concept_alignment.md). These files are part of the author's (FW1201) integrated ecosystem for educational tools and represent legitimate shared resources. - [DATA_EXFILTRATION]: While the skill mentions uploading to Google Drive, it includes a strict safety directive requiring the agent to display a confirmation summary and wait for explicit user approval before any write or upload operations occur.
Audit Metadata