rehearse-qa
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts, specifically 'scripts/qa_drill.py' and 'scripts/grade_answers.py', to perform its core functions of drill planning and timing analysis. A code review of these scripts confirms they rely exclusively on Python's standard library and do not perform any network operations or sensitive file system access.
- [DATA_EXFILTRATION]: The skill includes mandatory instructions for the agent to process user-provided documents transiently. It explicitly forbids copying or storing the text of papers or slides within the repository, ensuring that sensitive research data remains protected.
- [PROMPT_INJECTION]: The skill instructions contain proactive guardrails that define the agent's behavior as an honest coach. These guidelines require the agent to verify all citations using external tools, avoid inventing prior work, and refrain from misrepresenting research limitations, which effectively mitigates common injection and misinformation risks.
Audit Metadata