stitched-full-page-capture

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes ffmpeg and the macOS sips utility to perform image stitching and cropping. These tools are invoked using child_process.spawn and child_process.execFile without a shell, which is a secure implementation. Command arguments are either sanitized (numeric casting/regex validation) or derived from the project's own manifest file.
  • [EXTERNAL_DOWNLOADS]: The skill uses Playwright to automate a Chromium browser for navigating to URLs specified in a local manifest file. This interaction is the primary purpose of the skill and does not involve downloading and executing arbitrary remote scripts.
  • [DYNAMIC_EXECUTION]: The script uses module.createRequire to load the playwright library from the local workspace. This is a standard pattern for developer tools to use a project's existing dependencies rather than global ones and does not represent a malicious obfuscation or remote code execution threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:31 AM
Security Audit — agent-trust-hub — stitched-full-page-capture