doc-screenshots

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides instructions for executing a local Python script (scripts/annotate.py) and installing necessary automation dependencies. These actions are strictly for the purpose of processing images and capturing UI states as described in the workflow.
  • [EXTERNAL_DOWNLOADS]: The skill references standard package installation for playwright (maintained by Microsoft) and Pillow. These are well-known, trusted libraries in the developer community for browser automation and image manipulation.
  • [INDIRECT_PROMPT_INJECTION]: The annotate.py script processes JSON configuration files that contain text and coordinates for callouts.
  • Ingestion points: The script reads user-supplied configuration files via json.load().
  • Boundary markers: The workflow advises using programmatically determined bounding boxes to ensure precision.
  • Capability inventory: The script's capabilities are limited to reading image files and writing processed WEBP images and PNG crops to the local file system.
  • Sanitization: A robust validate() function is implemented to ensure all input JSON data follows the required schema and data types before any rendering occurs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 10:09 AM
Security Audit — agent-trust-hub — doc-screenshots