doc-screenshots
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for executing a local Python script (
scripts/annotate.py) and installing necessary automation dependencies. These actions are strictly for the purpose of processing images and capturing UI states as described in the workflow. - [EXTERNAL_DOWNLOADS]: The skill references standard package installation for
playwright(maintained by Microsoft) andPillow. These are well-known, trusted libraries in the developer community for browser automation and image manipulation. - [INDIRECT_PROMPT_INJECTION]: The
annotate.pyscript processes JSON configuration files that contain text and coordinates for callouts. - Ingestion points: The script reads user-supplied configuration files via
json.load(). - Boundary markers: The workflow advises using programmatically determined bounding boxes to ensure precision.
- Capability inventory: The script's capabilities are limited to reading image files and writing processed WEBP images and PNG crops to the local file system.
- Sanitization: A robust
validate()function is implemented to ensure all input JSON data follows the required schema and data types before any rendering occurs.
Audit Metadata