screenshot
Warn
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes multiple local scripts across different operating systems to perform its core functions.
- Evidence: SKILL.md provides instructions to run 'bash scripts/ensure_macos_permissions.sh', 'python3 scripts/take_screenshot.py', and 'powershell -ExecutionPolicy Bypass -File scripts/take_screenshot.ps1'.
- [DATA_EXFILTRATION]: The primary function of the skill is to capture visual information from the system, which inherently involves the exposure of potentially sensitive data to the agent's context.
- Evidence: scripts/take_screenshot.py and scripts/take_screenshot.ps1 utilize system APIs (e.g., screencapture on macOS, System.Drawing.Graphics.CopyFromScreen on Windows) to capture full-screen or window-specific imagery.
- [COMMAND_EXECUTION]: The skill explicitly bypasses system security policies on Windows to facilitate script execution.
- Evidence: SKILL.md uses the '-ExecutionPolicy Bypass' flag when invoking the PowerShell helper script.
- [COMMAND_EXECUTION]: The skill performs dynamic execution of native code to gather system metadata.
- Evidence: scripts/take_screenshot.py uses the 'swift' compiler/interpreter to execute multiple helper scripts (macos_permissions.swift, macos_window_info.swift, macos_display_info.swift) at runtime.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through system metadata.
- Evidence: scripts/macos_window_info.swift extracts window titles and application names from the operating system without significant sanitization (other than basic quote escaping in AppleScript). If a user has a window open with a malicious title, this content could influence subsequent agent behavior.
Audit Metadata