scrapfly-screenshot

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes the official scrapfly-sdk Python package for its core functionality.
  • [DATA_EXFILTRATION]: Network operations are restricted to the official vendor domain api.scrapfly.io for screenshot generation.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external URLs provided as user input to perform visual captures. While the content of these pages is external, the skill acts as a pass-through to the Scrapfly service and does not execute instructions from the page content within the local agent environment.
  • [CREDENTIALS_UNSAFE]: The skill correctly recommends using environment variables (SCRAPFLY_API_KEY) to manage authentication tokens rather than hardcoding credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 04:04 AM
Security Audit — agent-trust-hub — scrapfly-screenshot