screenshot-to-code

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the processing of untrusted visual data.- Ingestion points: The skill ingests 'attached screenshots or visual references' as its primary source of truth.- Boundary markers: While it instructs the agent to treat images as visual evidence, there are no instructions to disregard or delimit text found within the images that might contain malicious instructions (OCR-based injection).- Capability inventory: The agent is authorized to perform file operations and execute shell commands ('Run the project'), which could be leveraged if an injection is successful.- Sanitization: The instructions do not define any sanitization or validation steps for text extracted from screenshots.- [COMMAND_EXECUTION]: The verification workflow requires the execution of shell commands within the project environment.- Evidence: 'SKILL.md' contains the explicit instruction: 'Run the project and capture the implementation at each reference viewport.'- Context: While a standard part of a development workflow, this capability involves executing scripts defined in the user's repository, which represents a significant attack surface if the repository is compromised or malicious.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 08:36 PM
Security Audit — agent-trust-hub — screenshot-to-code