screenshot-url

Warn

Audited by Socket on Jul 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core screenshot capability generally matches the stated purpose, and install trust is relatively low risk because it uses a bundled Python file with no external installer. However, the skill routes data through a hosted third-party API, auto-registers and stores a token, instructs the agent to relay a provider-crafted activation link to a human, and allows the API base URL to be redirected, creating medium data-flow and trust concerns disproportionate to a simple screenshot helper.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Jul 24, 2026, 06:16 PM
Package URL
pkg:socket/skills-sh/toolshedlabs-hash%2Fweb-access-skills%2Fscreenshot-url%2F@ae223e74df141ceca3ce80f670bffe5a42c68c9ff031c9ad12b145912442fdc3
Security Audit — socket — screenshot-url