screenshot-critique
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external visual data (screenshots) which serves as an ingestion point for potentially untrusted content. Evidence chain: (1) Ingestion points: User-supplied PNG/GIF frames and crops. (2) Boundary markers: Uses
fork_context: falseand neutral prompts to isolate the sub-agent from project history. (3) Capability inventory: No file-write, network, or command execution capabilities are granted to the sub-agent. (4) Sanitization: None mentioned. The isolation strategy effectively mitigates these risks. - [SAFE]: The overall design demonstrates a secure approach to sub-agent orchestration by emphasizing fresh context and minimizing cross-contamination during visual reviews.
Audit Metadata