techsmith-security-basics

v2026.09.24

Harden Snagit and Camtasia automation around capture consent, license secrecy, local storage, share destinations, least privilege, and artifact review. Use when threat-modeling or approving a TechSmith workflow. Trigger with "TechSmith security", "secure Snagit automation", or "Camtasia data controls".

GitHub
安装命令
npx skhub add jeremylongshore/techsmith-security-basics
Markdown
SKILL.md

TechSmith Desktop Automation Security Boundary

Overview

Desktop capture and media production cross sensitive screen, microphone, camera, filesystem, cloud-sharing, and licensing boundaries. This skill makes those boundaries explicit and keeps automation narrower than an interactive user's full capabilities.

Prerequisites

  • Workflow, users, endpoints, product versions, and data classification
  • Approved capture subjects, devices, destinations, retention, and sharing policy
  • License model and secret owner
  • Deployment controls, endpoint protection, audit logging, and incident response

Tool Discipline

Use Read, Glob, and Grep to inspect local scripts, manifests, logs, and tests. Use WebFetch only for current primary TechSmith documentation. Use Write or Edit only after confirming the target repository file and approval boundary.

Current Contract

  • Software keys and offline activation artifacts are secrets; keep them out of code, chat, logs, and unrestricted process arguments.
  • Require explicit scope and consent for screen, microphone, camera, and clipboard operations.
  • Use allowlisted local input/output roots and promote only validated artifacts.
  • Use TechSmith deployment controls to disable unapproved share destinations or connected features rather than relying on operator memory.

Licensing and Authentication

TechSmith desktop activation is not API authentication. Resolve individual sign-in versus business-key or approved offline activation before execution. Redact all keys, account identifiers, activation artifacts, and sensitive endpoint details.

Instructions

  1. Map actors, endpoint privileges, capture devices, project/media paths, share outputs, activation flow, and downstream publishers.
  2. Classify threats: unintended capture, secret leakage, path traversal, malicious project/media, unauthorized upload, and persistence.
  3. Constrain worker identity, session access, COM/recorder operations, input/output roots, and network destinations.
  4. Configure approved deployment restrictions for sharing, updates, analytics, assets, or cloud features according to policy.
  5. Add redacted audit events for authorization, job identity, product/version, output hash, validation, promotion, and deletion.
  6. Exercise denial, cancellation, wrong-path, secret-scan, and incident-containment scenarios before approval.

Approval Boundaries

Do not disable endpoint security, broaden share outputs, record hidden devices, retain clipboard data, or upload artifacts merely to prove connectivity.

Output

Return assets, threats, controls, residual risks, data-flow boundaries, deployment restrictions, audit events, test evidence, and accountable owners.

Error Handling

ConditionResponse
Capture scope ambiguousDeny the job until subject, window/region, devices, and purpose are explicit.
Key appears in artifactQuarantine, rotate, and purge the affected history or bundle.
Output destination unapprovedBlock promotion and correct the allowlist.
Required control unsupportedChange the architecture or product workflow rather than accepting silent exposure.

Examples

The example below shows the minimum redacted evidence expected from a successful invocation of this operator workflow.

capture=approved-window; audio=disabled; output=local-allowlist; sharing=restricted; retention=7d; audit=pass

Resources

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

Sep 24, 2026

分类

未分类

许可证

MIT

源路径

skills/.curated/techsmith-security-basics

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8