compare-screenshots
Warn
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The scripts
visual-parity-diff.mjsandvisual-parity-diff.eval.mjsutilizecreateRequireandrequire.resolveto load thepngjsandpixelmatchlibraries. The paths for these libraries are computed at runtime based on theREPO_ROOTenvironment variable or the current working directory, which allows for dynamic loading of code from potentially untrusted directory structures. - [COMMAND_EXECUTION]: The test harness
visual-parity-diff.eval.mjsusesnode:child_processtospawnthe main script. While this is standard for automated testing, it involves executing shell commands where the script path is derived from the local environment. - [INDIRECT_PROMPT_INJECTION]: The skill processes external PNG images to provide a 'less wrong' verdict, creating a vulnerability surface for adversarial visual content.
- Ingestion points: External PNG files read from directories defined by
REFERENCE_DIRandCANDIDATE_DIRenvironment variables. - Boundary markers: The subagent instructions in
references/subagent-visual-review.mduse neutral labeling (Image A vs Image B) but do not include specific warnings or delimiters to prevent the agent from being influenced by instructions embedded within the images themselves. - Capability inventory: The skill can perform file system read/write operations to generate artifacts and can execute local Node.js scripts.
- Sanitization: Content is parsed using the
pngjslibrary, but there is no mechanism to sanitize or validate the visual content against prompt injection before the agent evaluates it.
Audit Metadata