Screenshot Api — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Screenshot Api (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Pixel-perfect website screenshot service that captures any URL as PNG, JPEG, or PDF. Exposed as both a REST API (FastAPI) and an MCP server for use with Claude Desktop, Cursor, and other MCP-compatible clients. Uses Playwright with a pooled Chromium browser for fast, reliable rendering.
docker-compose up -dThe API will be available at http://localhost:8500.
python -m venv .venv && source .venv/bin/activate
pip install -r requirements.txt
bash setup_browsers.sh
python server.pyAdd to your claude_desktop_config.json:
{
"mcpServers": {
"screenshot": {
"command": "python",
"args": ["/path/to/mcp-services/screenshot-api/mcp_server.py"]
}
}
}Add to your Cursor MCP settings:
{
"mcpServers": {
"screenshot": {
"command": "python",
"args": ["/path/to/mcp-services/screenshot-api/mcp_server.py"]
}
}
}{
"mcpServers": {
"screenshot": {
"command": "uvx",
"args": ["mcp-server-screenshot"]
}
}
}#### POST /screenshot
Take a screenshot with full control over parameters.
Request body (JSON):
| Parameter | Type | Default | Description |
|---|---|---|---|
url | string | required | URL to capture |
viewport_width | int | 1280 | Viewport width (320-3840) |
viewport_height | int | 720 | Viewport height (240-2160) |
full_page | bool | false | Capture entire scrollable page |
format | string | "png" | Output: "png", "jpeg", or "pdf" |
wait_for | string | null | CSS selector to wait for |
block_cookies | bool | false | Block cookie consent banners |
inject_css | string | null | Custom CSS to inject |
delay_ms | int | 0 | Extra delay after load (0-10000) |
Example:
curl -X POST http://localhost:8500/screenshot \
-H "Content-Type: application/json" \
-d '{"url": "https://example.com", "full_page": true, "format": "png"}' \
-o screenshot.png#### GET /screenshot
Simple GET-based screenshot (no CSS injection support).
curl "http://localhost:8500/screenshot?url=https://example.com&width=1920&height=1080&format=jpeg" -o screenshot.jpgQuery parameters: url, width, height, full_page, format, wait_for, block_cookies, delay_ms
#### POST /screenshot/base64
Same parameters as POST /screenshot, returns JSON with base64-encoded image.
curl -X POST http://localhost:8500/screenshot/base64 \
-H "Content-Type: application/json" \
-d '{"url": "https://example.com"}'Response:
{
"url": "https://example.com",
"format": "png",
"content_type": "image/png",
"base64": "iVBORw0KGgo...",
"size_bytes": 45231
}#### GET /health
Health check. Returns {"status": "ok"}.
#### GET /stats
Cache and usage statistics.
#### POST /admin/keys
Create API keys (requires X-Admin-Key header matching ADMIN_KEY env var).
curl -X POST "http://localhost:8500/admin/keys?key=my-api-key&tier=pro&owner=alice" \
-H "X-Admin-Key: your-admin-key"| Header | Description |
|---|---|
X-API-Key | Your API key. Omit for free tier. |
| Header | Description |
|---|---|
X-Cache-Key | Truncated cache key for debugging |
X-Rate-Remaining | Remaining requests today |
When used as an MCP server, two tools are available:
take_screenshotReturns the screenshot as a viewable image (ImageContent for PNG/JPEG, TextContent with base64 for PDF).
screenshot_to_base64Returns the screenshot as a base64 string in a TextContent response, suitable for passing to other tools or embedding.
Both tools accept: url, viewport_width, viewport_height, full_page, format, wait_for, inject_css.
| Tier | Daily Limit | Auth |
|---|---|---|
| Free | 100/day per IP | No key needed |
| Basic | 1,000/day | API key |
| Pro | 10,000/day | API key |
| Enterprise | 100,000/day | API key |
Screenshots are cached using SHA256(url + params) as the key. Default TTL is 1 hour (configurable via CACHE_TTL). Expired entries are cleaned up automatically every 30 minutes.
See .env.example for all options. Key settings:
CACHE_DIR - Where cached screenshots are stored (default: /data/cache)CACHE_TTL - Cache duration in seconds (default: 3600)MAX_FREE_DAILY - Free tier daily limit (default: 100)ADMIN_KEY - Secret key for the admin endpointsPORT - API port (default: 8500)The default docker-compose.yml limits the container to 2 CPU cores and 2GB RAM. Adjust in the deploy.resources section as needed.
The docker-compose file uses a named volume screenshot-data for the cache and SQLite database. To use a host directory instead:
volumes:
- /path/on/host:/data~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.