screenshot

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing system-level commands and scripts to perform its core functionality. It uses screencapture and osascript on macOS, scrot or gnome-screenshot on Linux, and PowerShell's CopyFromScreen API on Windows. All calls are made using argument lists which mitigate shell injection risks.
  • [PRIVILEGE_ESCALATION]: Documentation for the skill includes instructions to run PowerShell with the -ExecutionPolicy Bypass flag. This is a standard practice for running local automation scripts and does not constitute a malicious privilege escalation attempt in this context.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface for untrusted data, specifically application names (--app) and file paths (--path). While this represents a theoretical attack surface, the risk is minimal given the tool's intended use and the logic implemented:
  • Ingestion points: User-provided arguments passed to take_screenshot.py and take_screenshot.ps1 via the agent.
  • Boundary markers: None explicitly present in the instructions to the agent.
  • Capability inventory: The skill can write files to arbitrary paths and execute system commands for screen capture as documented in take_screenshot.py and take_screenshot.ps1.
  • Sanitization: Application names are escaped for use in AppleScript strings within take_screenshot.py, and coordinate inputs are validated as integers. Output paths are normalized and validated before writing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:59 PM
Security Audit — agent-trust-hub — screenshot