local-page-analysis-capture

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to call the surf browser automation tool and clipboard utility. These calls use argument lists rather than shell strings, and the binary paths are validated before execution to prevent arbitrary command injection.
  • [DATA_EXPOSURE]: The skill reads local files and captures screenshots to create a ZIP archive for analysis. To mitigate accidental exposure of sensitive information, the skill implements a redact_sensitive_text function to sanitize absolute paths and URLs from logs and includes explicit instructions to avoid bundling secrets like .env files or node_modules.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by packaging untrusted local HTML/JS files for analysis by downstream LLMs.
  • Ingestion points: The scripts/capture_lib.py script reads local file content and renders it via a browser tool in collect_local_files and run_capture.
  • Boundary markers: The skill does not insert specific delimiters or 'ignore' instructions into the captured source code, though it provides a suggested analysis prompt for the downstream LLM.
  • Capability inventory: The skill has capabilities for file system read/write (restricted to the local project and /tmp) and execution of browser automation commands via subprocess.
  • Sanitization: The skill redacts sensitive system paths and URI/URLs from its execution logs to prevent metadata leakage in the manifest.json file.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:00 PM
Security Audit — agent-trust-hub — local-page-analysis-capture