terminal-screenshots
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs AI agents on using the
vhscommand-line utility to execute terminal commands defined in.tapescripts to generate visual outputs. It also facilitates the runtime generation and execution of these scripts to produce reproducible terminal captures.\n- [EXTERNAL_DOWNLOADS]: The documentation provides standard installation procedures forvhsand its dependencies (ffmpeg,ttyd) using official package managers like Homebrew and DNF, as well as official Docker images from theghcr.io/charmbraceletrepository.\n- [PROMPT_INJECTION]: The skill defines a workflow where the agent processes.tapefiles. There is a potential attack surface if an agent processes scripts from untrusted external sources, though this is inherent to the functionality of terminal recording tools. Evidence: Agent reads/writes.tapefiles and executes them viavhs. Capabilities: Subprocess execution ofvhsCLI. Sanitization: None described. Boundaries: No explicit instructions provided to the agent regarding source verification.
Audit Metadata