screenshot-annotator
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it interpolates untrusted data from user instructions and text labels directly into the prompt template sent to the Gemini model.
- Ingestion points: The
instructionandtextarguments inscripts/annotate.pyaccept arbitrary user input. - Boundary markers: The prompt templates in
refine_promptandannotate_imagedo not use delimiters (e.g., XML tags or triple quotes) to isolate user-supplied instructions from the system's critical instructions. - Capability inventory: The skill possesses capabilities for reading local image files, writing files to the disk, and performing network operations via the Gemini API.
- Sanitization: There is no evidence of sanitization, escaping, or validation of the user-provided strings before they are embedded into the prompt.
Audit Metadata