compare-screenshots
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes screenshots of external user interfaces and web pages as primary data, which constitutes an indirect prompt injection surface. Adversarial content within the images could attempt to influence the agent's visual interpretation or the subagent's judgment.
- Ingestion points: PNG image files provided via the
CANDIDATE_DIRandREFERENCE_DIRenvironment variables to the comparison scripts. - Boundary markers: The
references/subagent-visual-review.mdfile includes explicit instructions for subagents to remain unbiased, judge solely based on visible pixels, and disregard prior conclusions or implementation details. - Capability inventory: The skill uses Node.js scripts capable of reading and writing to the local file system and spawning subprocesses for testing purposes.
- Sanitization: Visual content is processed as raw pixel data for mathematical metrics; no semantic sanitization or filtering of image content is performed.
- [COMMAND_EXECUTION]: The evaluation harness
scripts/visual-parity-diff.eval.mjsutilizes thenode:child_processmodule to spawn the main comparison script (visual-parity-diff.mjs) during testing. This execution is limited to internal tool verification and does not incorporate unsanitized user input into the shell environment.
Audit Metadata