agent-first-screenshots

Warn

Audited by Socket on Aug 15, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/capture-verify.mjs

This module is primarily an automation tool for screenshot capture and image-based verification, but it contains multiple high-risk misuse primitives. The most significant is unvalidated spec.preCapture being executed via Runtime.evaluate in the remote browser/runtime over a WebSocket connection. Additionally, it accepts wsUrl and outPath directly from CLI without validation, enabling arbitrary remote endpoint interaction and potential arbitrary filesystem writes/overwrites. There is no clear evidence of classic embedded malware (e.g., mining/backdoor/exfiltration) within this snippet, but the exposed execution and write capabilities substantially increase security risk when attacker-controlled inputs are possible.

Confidence: 70%Severity: 75%
Audit Metadata
Analyzed At
Aug 15, 2026, 02:20 AM
Package URL
pkg:socket/skills-sh/different-ai%2Fopenwork%2Fagent-first-screenshots%2F@e8f8a0c04e1a3a0d09f0f86e0b5fdf72c11e242ea1bd39c0d4ed3f3a3796087d
Security Audit — socket — agent-first-screenshots