question-bank
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The Python script
scripts/question_bank.pyis invoked via shell commands to interact with the service API. It strictly uses the Python standard libraryurllibfor networking and does not perform any arbitrary command execution or system-level modifications. - [DATA_EXFILTRATION]: The skill makes network requests to
tizhuang.qcscience.cc, the vendor's official domain. It handles sensitive credentials, such as API keys and session tokens, via environment variables. The instructions provide explicit safeguards to prevent the agent from leaking these secrets into the chat interface or logs. - [PROMPT_INJECTION]: The skill includes instructions to manage user interaction flows and protect sensitive data. A static analysis flag for concealment was evaluated and determined to be benign, as it pertains to preventing the display of credentials and managing the visibility of exam solutions to ensure educational integrity.
- [SAFE]: The skill implements local caching of an anonymous trial token at
~/.question-bank/trial.json. This is a routine mechanism for CLI applications to maintain session state across multiple invocations. - [DYNAMIC_EXECUTION]: The 'Builder handoff' feature uses Base64 encoding to serialize session state into a URL fragment. This is a legitimate data transport mechanism for the service's web-based paper builder and does not involve the execution of obfuscated code or remote scripts.
Audit Metadata