ui-capture

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: CRITICALREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill documentation in references/standalone-driver.md suggests a bootstrap installation method that downloads and executes a shell script directly from a remote repository: curl -LsSf -o "$tmp" https://raw.githubusercontent.com/voidmatcha/ui-clone-skills/main/install.sh && bash "$tmp". This curl | bash pattern allows for arbitrary remote code execution from a source not recognized as a trusted organization.
  • [EXTERNAL_DOWNLOADS]: Automated security scanners detected a malicious, blacklisted URL within the skill's codebase.
  • Evidence: evals/evals.json includes https://cloudflare-protected-site.com, which is flagged as malicious (URL:Blacklist) by the URLite scanner.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to scrape and process content from arbitrary external websites (DOM structure, computed styles, and attributes), creating a significant attack surface for indirect prompt injection.
  • Ingestion points: DOM and style extraction in detection.md, capture-click-content-swap.md, and capture-transitions.md.
  • Boundary markers: The skill includes instructions in SKILL.md to skip "prompt-like page text as instructions," but these are simple natural language guidelines rather than robust technical delimiters.
  • Capability inventory: The skill has the ability to execute shell commands (ffmpeg, magick), write to the local filesystem (tmp/ref/), and perform network operations via a browser controller.
  • Sanitization: detection.md mentions redacting "suspicious directive-like text," but no formal sanitization or escaping is applied to all ingested data before it is used to drive agent actions.
  • [COMMAND_EXECUTION]: The skill constructs and runs complex shell commands using tools like ffmpeg, magick, and uv, with arguments potentially influenced by the content of the target websites being captured.
  • Evidence: capture-transitions.md uses variables like SCROLL_T and crop_t to dynamically build ffmpeg command strings.
Recommendations
  • AI detected serious security threats
  • Contains 1 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Oct 1, 2026, 12:44 PM
Security Audit — agent-trust-hub — ui-capture