sn-ppt-doctor

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: In ppt_doctor/check_environment.py and ppt_doctor/checks.py, the skill uses subprocess.run to execute system commands such as node --version, npx playwright install --dry-run chromium, and python sn_agent_runner.py --help. These commands are strictly used to verify the presence and versioning of required system tools and sibling scripts.
  • [CREDENTIALS_UNSAFE]: In ppt_doctor/check_environment.py and ppt_doctor/checks.py, the skill verifies the presence of API keys like SN_API_KEY. It explicitly masks these values in its output, showing only whether they are set or unset. Additionally, ppt_doctor/interactive.py helps users manually write missing keys to a local .env file, which follows safe development practices for secret management.
  • [EXTERNAL_DOWNLOADS]: In ppt_doctor/check_environment.py, the skill invokes npx to check for Playwright's Chromium browser. This operation targets a well-known service and is used solely for environment validation purposes.
  • [INDIRECT_PROMPT_INJECTION]: In ppt_doctor/interactive.py, the skill ingests user input via interactive prompts to populate a local .env file. This ingestion point is limited to the tool's primary configuration purpose and results only in local file writes, presenting no significant vulnerability surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:39 AM
Security Audit — agent-trust-hub — sn-ppt-doctor