{"data":{"skill":{"slug":"humanleap-magicscreenshots","name":"magicscreenshots","icon":"📦","repo":"https://github.com/humanleap/agent-skills/tree/1eaefe1e9bc4f006ccce55793eb98055619e9a5d/skills/magicscreenshots","status":"approved","author":"humanleap","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"afcdbc25-9468-4615-ae50-361d0225f96f","skill_id":"30fc3c60-6787-4f50-b379-dd7289509ad3","version":1,"content_hash":"v3:f34d6380f82ea59b1965530a3bc0b1bc54c25f91:7c7e511189b51fca4838829623c9882821ffa43f7fd2a58345626fc7ecd134ce:e3982443d6a875173e4fbec8693f7fe21598c25d2e3b9f795b4672054cad5781:736b696c6c732f68756d616e6c6561702f6d6167696373637265656e73686f7473:c021a068b5ab4e384e9372745bf6ae91","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 27 static findings are false positives in this documentation context, including Markdown backticks, service URLs, and misclassified screenshot and authentication language. Setup commands invoke external packages, but no malicious execution, covert capture, reconnaissance, or credential exfiltration instructions were found. Remote service and package implementations were not reviewed; the skill requires secure authentication, spending consent, and design approval.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":21,"line_start":17},{"file":"SKILL.md","line_end":27,"line_start":21},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":36,"line_start":36},{"file":"SKILL.md","line_end":37,"line_start":37},{"file":"SKILL.md","line_end":38,"line_start":38},{"file":"SKILL.md","line_end":39,"line_start":39},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":48,"line_start":47},{"file":"SKILL.md","line_end":48,"line_start":48},{"file":"SKILL.md","line_end":49,"line_start":49},{"file":"SKILL.md","line_end":51,"line_start":50},{"file":"SKILL.md","line_end":51,"line_start":51},{"file":"SKILL.md","line_end":52,"line_start":52},{"file":"SKILL.md","line_end":58,"line_start":57},{"file":"SKILL.md","line_end":58,"line_start":58}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":13,"line_start":13},{"file":"SKILL.md","line_end":63,"line_start":63},{"file":"SKILL.md","line_end":64,"line_start":64},{"file":"SKILL.md","line_end":65,"line_start":65},{"file":"SKILL.md","line_end":66,"line_start":66}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":78,"audit_model":"codex","audited_at":"2026-10-03T12:58:13.11+00:00","created_at":"2026-10-03T14:02:32.394625+00:00","static_findings":[{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Install this skill with `pnpm dlx skills add Humanleap/agent-skills --skill magicscreenshots`. Conne","category":"external_commands","line_end":13,"severity":"medium","line_start":13},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":21,"severity":"medium","line_start":17},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":27,"severity":"medium","line_start":21},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Approve spending before starting.** Confirm the paid operation and the human’s spending limit b","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Define the brief.** Identify the app category, audience and desired feel. Read `list_directory_","category":"external_commands","line_end":36,"severity":"medium","line_start":36},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Search references.** Use `list_directory_apps` by query, category, chart (`free` or `grossing`)","category":"external_commands","line_end":37,"severity":"medium","line_start":37},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Inspect the images.** Read `get_directory_app` and `get_directory_screens` for a few candidates","category":"external_commands","line_end":38,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Prepare the user's generation.** After secure authentication and spending approval, use `get_sc","category":"external_commands","line_end":39,"severity":"medium","line_start":39},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Review and finish.** Poll `get_job_group` for `overview_url`, show it, and call `approve_restyl","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `list_directory_categories`, `list_directory_tags` | Discover categories and listing looks. |","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `list_directory_apps` | Search app listings; returned slugs identify apps. |","category":"external_commands","line_end":48,"severity":"medium","line_start":47},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `get_directory_app`, `get_directory_screens` | Listing details and ordered screenshots. |","category":"external_commands","line_end":48,"severity":"medium","line_start":48},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `get_app_videos`, `get_app_history` | Preview references or past listings; Pro access applies to d","category":"external_commands","line_end":49,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `get_screenshots` | Identify the user's source app/screenshots. |","category":"external_commands","line_end":51,"severity":"medium","line_start":50},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `create_restyle`, `create_localize` | Start requested screenshot generation or translation. |","category":"external_commands","line_end":51,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `get_job_group`, `approve_restyle`, `list_results` | Inspect jobs, approve the overview and retrie","category":"external_commands","line_end":52,"severity":"medium","line_start":52},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Restyle:** use the chosen reference slug, for example `{\"source_app\":{\"query\":\"My App\"},\"inspira","category":"external_commands","line_end":58,"severity":"medium","line_start":57},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Localization:** use `create_localize` with the user's selected `target_locales`, such as `[\"JPN\"","category":"external_commands","line_end":58,"severity":"medium","line_start":58},{"id":"network:SKILL.md:4:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"metadata: {\"homepage\":\"https://www.magicscreenshots.com/agents\",\"openclaw\":{\"emoji\":\"🪄\",\"requires\":","category":"network","line_end":4,"severity":"low","line_start":4},{"id":"network:SKILL.md:13:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"Install this skill with `pnpm dlx skills add Humanleap/agent-skills --skill magicscreenshots`. Conne","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"network:SKILL.md:63:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Agent setup: https://www.magicscreenshots.com/agents","category":"network","line_end":63,"severity":"low","line_start":63},{"id":"network:SKILL.md:64:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Library: https://www.magicscreenshots.com/apps","category":"network","line_end":64,"severity":"low","line_start":64},{"id":"network:SKILL.md:65:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Charts: https://www.magicscreenshots.com/top","category":"network","line_end":65,"severity":"low","line_start":65},{"id":"network:SKILL.md:66:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"- Pricing: https://www.magicscreenshots.com/pricing","category":"network","line_end":66,"severity":"low","line_start":66},{"id":"blocker:SKILL.md:70:screen-capture-upload","file":"SKILL.md","pattern":"Screen capture upload","snippet":"- The library contains App Store listing marketing screenshots, rather than arbitrary in-app UI capt","category":"blocker","line_end":70,"severity":"high","line_start":70},{"id":"blocker:SKILL.md:27:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"3. **Approve spending before starting.** Confirm the paid operation and the human’s spending limit b","category":"blocker","line_end":27,"severity":"low","line_start":27},{"id":"blocker:SKILL.md:32:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"Public library search/read tools need no key. For authenticated features, the human sets up a suppor","category":"blocker","line_end":32,"severity":"low","line_start":32}],"finding_verdicts":[{"id":"external_commands:SKILL.md:13:ruby-shell-backtick-execution","reason":"Backticks format a fixed skill installation command and MCP URL, not Ruby execution or shell substitution. Package installation is explicit setup, not hidden execution.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:17:ruby-shell-backtick-execution","reason":"This is a Markdown bash fence containing fixed search, app lookup, and screenshot download examples. No backtick substitution or injected shell input appears.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:21:ruby-shell-backtick-execution","reason":"The matched text closes a Markdown code block. Subsequent prose states workflow safeguards, not executable shell or Ruby code.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"Inline backticks label MCP tools in a rule requiring spending and design approval. They do not execute commands.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:36:ruby-shell-backtick-execution","reason":"Backticks format category and tag lookup tool names in a design briefing step. There is no Ruby expression or shell command substitution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:37:ruby-shell-backtick-execution","reason":"The line documents an app search tool and fixed chart and platform parameters. Backticks are Markdown formatting, not shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The formatted identifiers are tools for reading listing details and marketing screenshots. No shell or Ruby execution is present.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:39:ruby-shell-backtick-execution","reason":"Backticks name screenshot and restyling tools and their parameters. The workflow explicitly requires secure authentication and spending approval before generation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"Backticks label job polling and design approval tools, not executable shell syntax. Approval is deferred until the human reviews the overview.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"This table row formats two directory lookup tool names. It contains no shell or Ruby code.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:47:ruby-shell-backtick-execution","reason":"The table documents library search and listing read tools. Markdown backticks do not indicate command execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:48:ruby-shell-backtick-execution","reason":"The row labels tools returning listing details and ordered screenshots. No executable shell or Ruby expression appears.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"Backticks format preview and listing history tool names. The row also discloses Pro access requirements rather than bypassing them.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:50:ruby-shell-backtick-execution","reason":"These table rows name source screenshot and generation tools. Backticks are formatting, and the preceding rules require approval for paid operations.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The row describes requested screenshot generation and translation through MCP tools. It contains no shell substitution, and spending consent is required elsewhere.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:52:ruby-shell-backtick-execution","reason":"Backticks label tools for job inspection, overview approval, and result retrieval. This is a documentation table, not command execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:57:ruby-shell-backtick-execution","reason":"Inline examples show structured restyling parameters and localization tool names. Markdown backticks do not evaluate the example data.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:58:ruby-shell-backtick-execution","reason":"The localization example formats a tool name, parameter name, and fixed locale list. There is no Ruby execution or shell substitution.","verdict":"false_positive","confidence":1},{"id":"network:SKILL.md:4:hardcoded-url","reason":"The URL identifies the advertised service homepage in metadata. No request or sensitive data transmission is specified.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:13:hardcoded-url","reason":"The HTTPS URL is the disclosed MagicScreenshots MCP endpoint for the intended integration. No covert recipient or credential transmission instruction appears.","verdict":"false_positive","confidence":0.97},{"id":"network:SKILL.md:63:hardcoded-url","reason":"This is a supporting link to the advertised service's agent setup page. It does not specify an upload or automated request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:64:hardcoded-url","reason":"This link points to the service's app reference library, matching the research workflow. No data exfiltration instruction accompanies it.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:65:hardcoded-url","reason":"The service's charts page is listed as a research resource. The URL alone does not direct sensitive data transmission.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:66:hardcoded-url","reason":"The pricing link supports transparent cost review for the documented paid workflow. It contains no secrets or hidden destination.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:70:screen-capture-upload","reason":"The sentence distinguishes public listing marketing screenshots from arbitrary in-app UI captures. It instructs neither screen capture nor uploading.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:27:system-reconnaissance","reason":"This rule requires human approval of spending limits and design choices. It does not inspect system information or enumerate local resources.","verdict":"false_positive","confidence":1},{"id":"blocker:SKILL.md:32:system-reconnaissance","reason":"The authentication guidance prohibits requesting, printing, saving, or transmitting credentials in conversation or tool arguments. It contains no system reconnaissance instructions.","verdict":"false_positive","confidence":1}],"semantic_findings":[],"subject_marketplace_commit_sha":"f34d6380f82ea59b1965530a3bc0b1bc54c25f91","subject_content_hash":"7c7e511189b51fca4838829623c9882821ffa43f7fd2a58345626fc7ecd134ce","subject_tree_hash":"e3982443d6a875173e4fbec8693f7fe21598c25d2e3b9f795b4672054cad5781","subject_plugin_path":"skills/humanleap/magicscreenshots","audit_payload_hash":"c021a068b5ab4e384e9372745bf6ae91","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"f34d6380f82ea59b1965530a3bc0b1bc54c25f91","contentHash":"7c7e511189b51fca4838829623c9882821ffa43f7fd2a58345626fc7ecd134ce","treeHash":"e3982443d6a875173e4fbec8693f7fe21598c25d2e3b9f795b4672054cad5781","pluginPath":"skills/humanleap/magicscreenshots","auditPayloadHash":"c021a068b5ab4e384e9372745bf6ae91"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/humanleap-magicscreenshots/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}