annotate-screenshots

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the uploads command-line tool to perform core operations, including capturing live web pages and applying visual annotations (boxes, arrows, labels, and redactions) to images.
  • [EXTERNAL_DOWNLOADS]: The uploads screenshot command fetches content from remote URLs provided by the user to generate screenshots.
  • [DATA_EXFILTRATION]: The skill documentation explicitly warns that objects uploaded to uploads.sh are public. It provides a redact annotation type with a solid style specifically to mitigate the risk of exposing secrets like API keys or tokens in shared screenshots.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 05:21 PM
Security Audit — agent-trust-hub — annotate-screenshots