sn-ppt-doctor
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: In
ppt_doctor/check_environment.pyandppt_doctor/checks.py, the skill usessubprocess.runto execute system commands such asnode --version,npx playwright install --dry-run chromium, andpython sn_agent_runner.py --help. These commands are strictly used to verify the presence and versioning of required system tools and sibling scripts. - [CREDENTIALS_UNSAFE]: In
ppt_doctor/check_environment.pyandppt_doctor/checks.py, the skill verifies the presence of API keys likeSN_API_KEY. It explicitly masks these values in its output, showing only whether they are set or unset. Additionally,ppt_doctor/interactive.pyhelps users manually write missing keys to a local.envfile, which follows safe development practices for secret management. - [EXTERNAL_DOWNLOADS]: In
ppt_doctor/check_environment.py, the skill invokesnpxto check for Playwright's Chromium browser. This operation targets a well-known service and is used solely for environment validation purposes. - [INDIRECT_PROMPT_INJECTION]: In
ppt_doctor/interactive.py, the skill ingests user input via interactive prompts to populate a local.envfile. This ingestion point is limited to the tool's primary configuration purpose and results only in local file writes, presenting no significant vulnerability surface.
Audit Metadata