browser-video-recording

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The bundled script scripts/render_browser_demo.py executes several external binaries via subprocess calls.
  • It invokes swift to perform cursor extraction using an embedded script.
  • It calls ffmpeg with numerous arguments to process raw video frames into an MP4 file.
  • It utilizes /usr/sbin/screencapture (via the Swift sub-process) to capture screen regions for matte generation.
  • [REMOTE_CODE_EXECUTION]: The skill performs dynamic code execution by passing a multi-line Swift source string (SWIFT_CURSOR_CAPTURE) to the swift interpreter's standard input.
  • [INDIRECT_PROMPT_INJECTION]: The rendering pipeline processes external data which could be manipulated to influence the execution environment.
  • Ingestion points: scripts/render_browser_demo.py reads data from user-supplied JSON configuration files (--config) and PNG image files (shots).
  • Boundary markers: There are no explicit boundary markers or validation steps to ensure the integrity of the processed image content or the complexity of the JSON configuration.
  • Capability inventory: The skill has the ability to write to the file system (temporary directories and output paths) and execute shell commands.
  • Sanitization: While arguments are passed to subprocess as lists (reducing standard shell injection risks), the values within the JSON config (such as file paths and preset names) are used directly in command construction.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:31 AM
Security Audit — agent-trust-hub — browser-video-recording