Ppx Parse

Security checks across static analysis, malware telemetry, and agentic risk

Overview

The skill's requirements, instructions, and included scripts align with its stated purpose (invoking a local `ppx` CLI to OCR/parse documents); nothing requested or installed is disproportionate or unexplained.

This skill appears coherent and limited to invoking and configuring the local `ppx` CLI. Before installing or running it: (1) ensure you install `memect-ppx` and dependencies from trusted package sources (pip) and in a virtual environment to avoid system-wide package changes; (2) only configure remote LLM backends or provide API keys if you trust the endpoint (the examples default to localhost but flags accept remote URLs); (3) note that sync_version.py will write to SKILL.md if run — treat it as a repo-maintenance helper and avoid running it on unexpected directories; and (4) if you need higher assurance, inspect the contents of the pip package you install (memect-ppx) or run it in an isolated environment. Overall the skill is internally consistent with its stated purpose.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

No visible risk-analysis findings were reported for this release.