Guidance for using webcam, screen capture, and image analysis.
Security
2 findings: 1 critical severity, 1 high severity. Installing this skill is not recommended: please review these findings carefully if you do intend to do so.
Detected high-risk code patterns in the skill content — including its prompts, tool definitions, and resources — such as data exfiltration, backdoors, remote code execution, credential theft, system compromise, supply chain attacks, and obfuscation techniques.
The skill explicitly instructs the agent to access the user's webcam/screen and to automatically call analyze_image without clarification or consent, which is a deliberate privacy-invasive behavior enabling unauthorized data collection.
The skill handles credentials insecurely by requiring the agent to include secret values verbatim in its generated output. This exposes credentials in the agent’s context and conversation history, creating a risk of data exfiltration.
The skill mandates immediate image analysis of the user's webcam/screen and telling the model to "Describe everything you see" (or pass the user's question verbatim), which can force the model to transcribe and output any visible secrets (passwords, API keys, tokens) captured by the camera/screen.
b4dcda4
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.