screenshot-url
Warn
Audited by Socket on Jul 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core screenshot capability generally matches the stated purpose, and install trust is relatively low risk because it uses a bundled Python file with no external installer. However, the skill routes data through a hosted third-party API, auto-registers and stores a token, instructs the agent to relay a provider-crafted activation link to a human, and allows the API base URL to be redirected, creating medium data-flow and trust concerns disproportionate to a simple screenshot helper.
Confidence: 84%Severity: 56%
Audit Metadata