Back to skill

Security audit

Screenshot Capture

Security checks across malware telemetry and agentic risk

Overview

This skill transparently saves user-shared screenshots into local notes and reminders, with privacy cautions but no evidence of hidden, destructive, or exfiltrating behavior.

Install this only if you want screenshot contents saved locally and summarized into notes, with a one-week reminder created by default. Avoid using it on screenshots containing passwords, tokens, private messages, financial data, or proprietary material, and tell the agent clearly when you do not want a screenshot saved or a reminder created.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broad enough that it could activate on routine screenshot sharing without strong user intent to invoke this workflow. That increases the chance of unintended file writes, note creation, and reminder setting based on sensitive or irrelevant screenshots, which is risky because the skill persistently stores extracted content and metadata.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The workflow says to execute when Enzo shares a screenshot with comments, but it does not define sufficient guardrails or disambiguation checks before performing actions. In context, this is more dangerous because the skill automatically copies files, extracts content, updates multiple notes, and always sets a reminder, so accidental triggering can cause privacy leaks, unwanted persistence, and noisy automation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.