Back to skill

Security audit

SnapRender

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent SnapRender screenshot/page-reading integration, but it also includes under-disclosed remote page monitoring that can persist and send email notifications.

Install only if you are comfortable sending target URLs, screenshots, and extracted page content to SnapRender. Avoid using it on internal, authenticated, confidential, regulated, or non-consensual targets unless the user explicitly approves. Treat the page-watching feature as a persistent remote monitor and confirm the exact URL, notification behavior, and how to disable it before creating any schedule.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

| curl -sS -X POST "https://app.snap-render.com/v1/screenshot"
-H "X-API-Key: $SNAPRENDER_API_KEY" -H "Content-Type: application/json"
-d @- -o "$OUT" -w '%{http_code}') if [ "$code" = 200 ]; then echo "saved $OUT ($(wc -c < "$OUT" | tr -d " ") bytes)"; else echo "error $code: $(cat "$OUT")"; rm -f "$OUT"; fi

text

Then:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation language is broad enough to overlap with many generic browsing, checking, comparing, or reading tasks, which can cause the skill to be selected in situations where users do not expect an external screenshotting service to receive the target URL or page content. Overbroad routing increases unintended data disclosure and use of third-party services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill does not prominently warn that using it transmits the requested URL and, for extraction, page content to the SnapRender service. Without a user-facing disclosure, agents may send internal, sensitive, or private URLs to a third party without informed consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This command sends a user-supplied URL to an external API along with an API credential, causing third-party transmission of browsing targets and capture results. In the context of a screenshotting skill this is expected behavior, but it is still security-relevant because it can expose sensitive URLs or page states to an outside service.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
mkdir -p snaprender && OUT="$PWD/snaprender/shot-$(date +%Y%m%d-%H%M%S)-$$.jpg"
code=$(jq -n --arg url 'TARGET_URL' \
  '{url: $url, format: "jpeg", quality: 80, block_ads: true, block_cookie_banners: true}' \
| curl -sS -X POST "https://app.snap-render.com/v1/screenshot" \
  -H "X-API-Key: $SNAPRENDER_API_KEY" -H "Content-Type: application/json" \
  -d @- -o "$OUT" -w '%{http_code}')
if [ "$code" = 200 ]; then echo "saved $OUT ($(wc -c < "$OUT" | tr -d " ") bytes)"; else echo "error $code: $(cat "$OUT")"; rm -f "$OUT"; fi

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The extract endpoint transmits the requested URL to a third party and returns page content, potentially including sensitive text from non-public pages. This is an intended feature, but without strong disclosure and consent requirements it can leak confidential content outside the local environment.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

bash
jq -n --arg url 'TARGET_URL' '{url: $url, type: "markdown", max_length: 20000}' \
| curl -sS -X POST "https://app.snap-render.com/v1/extract" \
  -H "X-API-Key: $SNAPRENDER_API_KEY" -H "Content-Type: application/json" -d @- \
| jq -r 'if .content then .content else . end'

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises screenshotting and page reading, but also includes a separate capability to create persistent remote monitoring schedules with change detection and email notifications. That materially expands the operational scope from one-shot retrieval into ongoing surveillance, which can surprise users and create privacy, consent, and abuse risks if invoked without explicit user approval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Persistent page watching and email notification are not necessary for the stated purpose of capturing or reading a page on demand. This mismatch increases the chance the skill could be used for covert or long-lived monitoring beyond user expectations, especially since it delegates ongoing observation to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The scheduled monitoring section lacks a warning that monitoring persists remotely and can trigger email notifications outside the current session. This creates additional privacy and consent risk because the user may not realize they are initiating ongoing third-party observation rather than a one-time action.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

Creating schedules sends target URLs and monitoring preferences to a third-party service for persistent processing, which expands exposure beyond a single request. Because the monitoring is ongoing and can generate notifications, misuse could enable sustained tracking of pages without adequate transparency or authorization.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

bash
jq -n --arg url 'TARGET_URL' '{url: $url, interval: "daily", change_threshold: 0.5, notify_email: true}' \
| curl -sS -X POST "https://app.snap-render.com/v1/schedules" \
  -H "X-API-Key: $SNAPRENDER_API_KEY" -H "Content-Type: application/json" -d @- | jq .

Static analysis

No suspicious patterns detected.