screenshot

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
screenshot_cli.sh

No clear malware indicators (no network/exfiltration, no credential access, no persistence, no obfuscation) are present in this fragment. However, it is an externally triggerable, privacy-invasive capability (screen/window/region capture) driven by untrusted input, and it allows caller-controlled destination paths without validation, enabling arbitrary file writes within the executing user's permissions. Main risk is misuse in a supply-chain or automation context, plus potential information leakage via returned local paths.

Confidence: 72%Severity: 62%
Audit Metadata
Analyzed At
Apr 11, 2026, 10:48 AM
Package URL
pkg:socket/skills-sh/DotNetAge%2Fmindx%2Fscreenshot%2F@4c93b7f6dce94829f03f7ea10f5f31c1cca3dd1b