cleanshotx
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill facilitates automation of the legitimate CleanShot X application via its documented URL scheme. All interactions are local to the user's macOS environment and intended for productivity.- [COMMAND_EXECUTION]: Employs standard macOS command-line utilities such as
opento trigger URL schemes,pbpasteto read OCR results from the clipboard, anddefaultsto check application versions. These are appropriate for the skill's stated purpose.- [INDIRECT_PROMPT_INJECTION]: The skill documents the use of OCR functionality (capture-text) which ingests data from screen regions or image files into the clipboard. While this represents a vulnerability surface for indirect prompt injection from processed images, it is an inherent feature of the automated tool and no malicious logic or bypasses were detected.- [EXTERNAL_DOWNLOADS]: References the officialcleanshot.comdomain for documentation and installation purposes, which is the legitimate and well-known service for the application being automated.
Audit Metadata