compare-screenshots

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes screenshots of external user interfaces and web pages as primary data, which constitutes an indirect prompt injection surface. Adversarial content within the images could attempt to influence the agent's visual interpretation or the subagent's judgment.
  • Ingestion points: PNG image files provided via the CANDIDATE_DIR and REFERENCE_DIR environment variables to the comparison scripts.
  • Boundary markers: The references/subagent-visual-review.md file includes explicit instructions for subagents to remain unbiased, judge solely based on visible pixels, and disregard prior conclusions or implementation details.
  • Capability inventory: The skill uses Node.js scripts capable of reading and writing to the local file system and spawning subprocesses for testing purposes.
  • Sanitization: Visual content is processed as raw pixel data for mathematical metrics; no semantic sanitization or filtering of image content is performed.
  • [COMMAND_EXECUTION]: The evaluation harness scripts/visual-parity-diff.eval.mjs utilizes the node:child_process module to spawn the main comparison script (visual-parity-diff.mjs) during testing. This execution is limited to internal tool verification and does not incorporate unsanitized user input into the shell environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 09:46 PM
Security Audit — agent-trust-hub — compare-screenshots