sn-ppt-entry

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing several localized Python scripts (parse_user_docs.py, caption_images.py, launch_workbench.py) to process user attachments and manage the generation lifecycle.
  • [DYNAMIC_EXECUTION]: The orchestration logic involves generating and running dynamic Python snippets using python3 -c. These snippets handle document data and facilitate communication with the SenseNova LLM for summarization purposes.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted text from user-uploaded files, creating a vulnerability surface.
  • Ingestion points: scripts/parse_user_docs.py extracts text from PDF, DOCX, Markdown, and TXT files.
  • Boundary markers: The prompts/document_digest.md file defines a strict JSON output format to guide the LLM, although it lacks specific delimiters for the ingested text.
  • Capability inventory: The skill possesses the ability to execute shell commands, write persistent JSON files to the local filesystem, and make network requests to SenseNova APIs.
  • Sanitization: Input data is truncated to a maximum character length in scripts/parse_user_docs.py before being sent to the LLM.
  • [EXTERNAL_DOWNLOADS]: The skill includes checks for Node.js and may suggest that the user install it or other dependencies to enable the workbench features.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:39 AM
Security Audit — agent-trust-hub — sn-ppt-entry