terminal-screenshots

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs AI agents on using the vhs command-line utility to execute terminal commands defined in .tape scripts to generate visual outputs. It also facilitates the runtime generation and execution of these scripts to produce reproducible terminal captures.\n- [EXTERNAL_DOWNLOADS]: The documentation provides standard installation procedures for vhs and its dependencies (ffmpeg, ttyd) using official package managers like Homebrew and DNF, as well as official Docker images from the ghcr.io/charmbracelet repository.\n- [PROMPT_INJECTION]: The skill defines a workflow where the agent processes .tape files. There is a potential attack surface if an agent processes scripts from untrusted external sources, though this is inherent to the functionality of terminal recording tools. Evidence: Agent reads/writes .tape files and executes them via vhs. Capabilities: Subprocess execution of vhs CLI. Sanitization: None described. Boundaries: No explicit instructions provided to the agent regarding source verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 12:50 PM
Security Audit — agent-trust-hub — terminal-screenshots