Back to skill

Security audit

Corespeed Excalidraw Rendering

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward screenshot and Excalidraw rendering helper, with disclosed network downloads and local image output that fit its purpose.

Install only if you trust the Corespeed brow CLI and are comfortable running an unpinned remote installer plus a managed Chrome download. Use explicit, user-chosen input files, URLs, and output paths, and avoid screenshotting sensitive authenticated pages unless you intend the browser-rendered content to be captured locally.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs the agent to install a browser, fetch remote content, capture website screenshots, and write image files locally, but it does not clearly warn the user that these actions require outbound network access and local file creation. In an agent setting, that omission can cause users to approve actions without understanding that remote downloads and local persistence will occur, increasing the risk of unintended network use and filesystem side effects.

Static analysis

No suspicious patterns detected.