browser-video-recording
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The bundled script
scripts/render_browser_demo.pyexecutes several external binaries viasubprocesscalls. - It invokes
swiftto perform cursor extraction using an embedded script. - It calls
ffmpegwith numerous arguments to process raw video frames into an MP4 file. - It utilizes
/usr/sbin/screencapture(via the Swift sub-process) to capture screen regions for matte generation. - [REMOTE_CODE_EXECUTION]: The skill performs dynamic code execution by passing a multi-line Swift source string (
SWIFT_CURSOR_CAPTURE) to theswiftinterpreter's standard input. - [INDIRECT_PROMPT_INJECTION]: The rendering pipeline processes external data which could be manipulated to influence the execution environment.
- Ingestion points:
scripts/render_browser_demo.pyreads data from user-supplied JSON configuration files (--config) and PNG image files (shots). - Boundary markers: There are no explicit boundary markers or validation steps to ensure the integrity of the processed image content or the complexity of the JSON configuration.
- Capability inventory: The skill has the ability to write to the file system (temporary directories and output paths) and execute shell commands.
- Sanitization: While arguments are passed to
subprocessas lists (reducing standard shell injection risks), the values within the JSON config (such as file paths and preset names) are used directly in command construction.
Audit Metadata