sn-ppt-workbench

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/open_workbench.py

This module primarily functions as a local orchestrator and WebUI launcher, not as self-contained malicious logic. However, it has meaningful security risk typical of supply-chain/host-compromise scenarios: it executes a local .mjs launcher path that can be influenced by environment variables and local filesystem state without integrity verification, and it forwards sensitive configuration (including API keys and a free-form --acp-command) to the launched runtime. It also sends Bearer tokens to a configured gateway during a probing step. If an attacker can influence the environment variables, .env contents, or the launcher file location on disk, the impact could be substantial (process-execution trust boundary).

Confidence: 60%Severity: 63%
Audit Metadata
Analyzed At
Jul 30, 2026, 08:45 PM
Package URL
pkg:socket/skills-sh/opensensenova%2Fsensenova-skills%2Fsn-ppt-workbench%2F@21c6f9f9d96c46d460db9b65fac08456fc798cd3181eb32ed4e9efaaa484ce64
Security Audit — socket — sn-ppt-workbench