stitched-full-page-capture
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The
stitch_full_page_capture.mjsscript executes system commandsffmpegandsipsvia subprocesses to perform image manipulation, cropping, and metadata extraction. - [INDIRECT_PROMPT_INJECTION]: The skill processes an external
manifest.jsonfile that specifies target URLs and output file paths, creating a vulnerability surface for indirect injection. - Ingestion points: The script reads and parses the
manifest.jsonfile specified by the--manifestargument institch_full_page_capture.mjs. - Boundary markers: No delimiters, sanitization, or "ignore embedded instructions" warnings are present for the data ingested from the manifest.
- Capability inventory: The skill possesses network and local file system access through Playwright (
page.goto), the ability to write files (fs.writeFile), and the capability to execute subprocesses (ffmpeg,sips). - Sanitization: The script lacks validation or filtering for the
item.pageUrlfield. An attacker providing a malicious manifest could trigger Local File Disclosure (usingfile:///protocols) or Server-Side Request Forgery (SSRF) against internal services. - [DYNAMIC_EXECUTION]: The script dynamically loads the
playwrightlibrary from the host environment's workspace using thecreateRequiremethod.
Audit Metadata