screenshot-loop
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user input from trigger phrases to define a numerical value for the
INTERVALvariable within a bash script. This creates an indirect prompt injection surface. - Ingestion points: User prompt text extracted during trigger phrase matching (e.g., 'alle 5 Sekunden').
- Boundary markers: None identified in the prompt template.
- Capability inventory: Execution of local bash scripts, ADB commands, and filesystem creation (
mkdir). - Sanitization: The skill provides natural language instructions for the agent to perform a 'sanity-check' (value must be between 0 and 60 and formatted with a dot) before interpolation.
- [COMMAND_EXECUTION]: The skill executes a bash block that calls a local script located at
~/proggs/scripts/screenshot.sh. This introduces a dependency on external code that must be pre-installed on the host system. - [COMMAND_EXECUTION]: The skill utilizes
adb shell cmd vibrator_managerto interact directly with hardware. The skill notes this bypasses system-level mute settings, representing a high-level of control over the connected Android device.
Audit Metadata