cleanshotx

Pass

Audited by Gen Agent Trust Hub on May 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill facilitates automation of the legitimate CleanShot X application via its documented URL scheme. All interactions are local to the user's macOS environment and intended for productivity.- [COMMAND_EXECUTION]: Employs standard macOS command-line utilities such as open to trigger URL schemes, pbpaste to read OCR results from the clipboard, and defaults to check application versions. These are appropriate for the skill's stated purpose.- [INDIRECT_PROMPT_INJECTION]: The skill documents the use of OCR functionality (capture-text) which ingests data from screen regions or image files into the clipboard. While this represents a vulnerability surface for indirect prompt injection from processed images, it is an inherent feature of the automated tool and no malicious logic or bypasses were detected.- [EXTERNAL_DOWNLOADS]: References the official cleanshot.com domain for documentation and installation purposes, which is the legitimate and well-known service for the application being automated.
Audit Metadata
Risk Level
SAFE
Analyzed
May 8, 2026, 04:33 AM