scrapfly-screenshot
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes the official
scrapfly-sdkPython package for its core functionality. - [DATA_EXFILTRATION]: Network operations are restricted to the official vendor domain
api.scrapfly.iofor screenshot generation. - [INDIRECT_PROMPT_INJECTION]: The skill ingests external URLs provided as user input to perform visual captures. While the content of these pages is external, the skill acts as a pass-through to the Scrapfly service and does not execute instructions from the page content within the local agent environment.
- [CREDENTIALS_UNSAFE]: The skill correctly recommends using environment variables (
SCRAPFLY_API_KEY) to manage authentication tokens rather than hardcoding credentials.
Audit Metadata