sn-image-doctor

Warn

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/check_environment.py performs dynamic module loading by manipulating sys.path at runtime. Specifically, it inserts a computed path (skills/sn-image-base/scripts) into the Python module search path to import the global_configs object. Loading code from dynamically constructed paths can lead to unexpected execution if the directory structure is modified by an attacker.\n- [DATA_EXFILTRATION]: The inspect_configs function prints the entire resolved configuration state to standard output using global_configs.to_string(). As this skill is designed to manage and validate sensitive credentials such as SN_API_KEY and SN_IMAGE_GEN_API_KEY, printing these values in diagnostic output poses a risk of accidental credential exposure in logs or terminal history if the configuration object does not implement proper field redaction.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 30, 2026, 06:52 AM
Security Audit — agent-trust-hub — sn-image-doctor