stitched-full-page-capture
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
ffmpegand the macOSsipsutility to perform image stitching and cropping. These tools are invoked usingchild_process.spawnandchild_process.execFilewithout a shell, which is a secure implementation. Command arguments are either sanitized (numeric casting/regex validation) or derived from the project's own manifest file. - [EXTERNAL_DOWNLOADS]: The skill uses Playwright to automate a Chromium browser for navigating to URLs specified in a local manifest file. This interaction is the primary purpose of the skill and does not involve downloading and executing arbitrary remote scripts.
- [DYNAMIC_EXECUTION]: The script uses
module.createRequireto load theplaywrightlibrary from the local workspace. This is a standard pattern for developer tools to use a project's existing dependencies rather than global ones and does not represent a malicious obfuscation or remote code execution threat.
Audit Metadata