screenshot-capture
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process content from external, untrusted URLs for the purpose of capturing screenshots. This introduces a potential surface for indirect prompt injection if the model attempts to parse or interpret data from the targeted web pages.
- Ingestion points: Target URLs processed by the
strale_screenshot_urlandcontext_dev_capture_screenshottools as described in SKILL.md and references/sandbase-api-map.md. - Boundary markers: The skill does not define specific delimiters or instructions to ignore instructions embedded within the target web pages.
- Capability inventory: The skill uses
sandbase_call_toolto execute the screenshot capture functionality (SKILL.md). - Sanitization: There are no explicit sanitization or validation procedures defined in the skill files for the content retrieved from external URLs.
Audit Metadata