compare-screenshots

Warn

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The scripts visual-parity-diff.mjs and visual-parity-diff.eval.mjs utilize createRequire and require.resolve to load the pngjs and pixelmatch libraries. The paths for these libraries are computed at runtime based on the REPO_ROOT environment variable or the current working directory, which allows for dynamic loading of code from potentially untrusted directory structures.
  • [COMMAND_EXECUTION]: The test harness visual-parity-diff.eval.mjs uses node:child_process to spawn the main script. While this is standard for automated testing, it involves executing shell commands where the script path is derived from the local environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external PNG images to provide a 'less wrong' verdict, creating a vulnerability surface for adversarial visual content.
  • Ingestion points: External PNG files read from directories defined by REFERENCE_DIR and CANDIDATE_DIR environment variables.
  • Boundary markers: The subagent instructions in references/subagent-visual-review.md use neutral labeling (Image A vs Image B) but do not include specific warnings or delimiters to prevent the agent from being influenced by instructions embedded within the images themselves.
  • Capability inventory: The skill can perform file system read/write operations to generate artifacts and can execute local Node.js scripts.
  • Sanitization: Content is parsed using the pngjs library, but there is no mechanism to sanitize or validate the visual content against prompt injection before the agent evaluates it.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 3, 2026, 02:29 PM
Security Audit — agent-trust-hub — compare-screenshots