stitched-full-page-capture

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The stitch_full_page_capture.mjs script executes system commands ffmpeg and sips via subprocesses to perform image manipulation, cropping, and metadata extraction.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes an external manifest.json file that specifies target URLs and output file paths, creating a vulnerability surface for indirect injection.
  • Ingestion points: The script reads and parses the manifest.json file specified by the --manifest argument in stitch_full_page_capture.mjs.
  • Boundary markers: No delimiters, sanitization, or "ignore embedded instructions" warnings are present for the data ingested from the manifest.
  • Capability inventory: The skill possesses network and local file system access through Playwright (page.goto), the ability to write files (fs.writeFile), and the capability to execute subprocesses (ffmpeg, sips).
  • Sanitization: The script lacks validation or filtering for the item.pageUrl field. An attacker providing a malicious manifest could trigger Local File Disclosure (using file:/// protocols) or Server-Side Request Forgery (SSRF) against internal services.
  • [DYNAMIC_EXECUTION]: The script dynamically loads the playwright library from the host environment's workspace using the createRequire method.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:59 PM
Security Audit — agent-trust-hub — stitched-full-page-capture