techsmith-security-basics
Harden Snagit and Camtasia automation around capture consent, license secrecy, local storage, share destinations, least privilege, and artifact review. Use when threat-modeling or approving a TechSmith workflow. Trigger with "TechSmith security", "secure Snagit automation", or "Camtasia data controls".
Allowed Tools
Provided by Plugin
techsmith-pack
18 source-grounded operator skills for safe Snagit and Camtasia desktop automation
Installation
This skill is included in the techsmith-pack plugin:
/plugin install techsmith-pack@claude-code-plugins-plus
Click to copy
Instructions
TechSmith Desktop Automation Security Boundary
Overview
Desktop capture and media production cross sensitive screen, microphone, camera, filesystem, cloud-sharing, and licensing boundaries. This skill makes those boundaries explicit and keeps automation narrower than an interactive user's full capabilities.
Prerequisites
- Workflow, users, endpoints, product versions, and data classification
- Approved capture subjects, devices, destinations, retention, and sharing policy
- License model and secret owner
- Deployment controls, endpoint protection, audit logging, and incident response
Tool Discipline
Use Read, Glob, and Grep to inspect local scripts, manifests, logs, and tests. Use WebFetch only for current primary TechSmith documentation. Use Write or Edit only after confirming the target repository file and approval boundary.
Current Contract
- Software keys and offline activation artifacts are secrets; keep them out of code, chat, logs, and unrestricted process arguments.
- Require explicit scope and consent for screen, microphone, camera, and clipboard operations.
- Use allowlisted local input/output roots and promote only validated artifacts.
- Use TechSmith deployment controls to disable unapproved share destinations or connected features rather than relying on operator memory.
Licensing and Authentication
TechSmith desktop activation is not API authentication. Resolve individual sign-in versus business-key or approved offline activation before execution. Redact all keys, account identifiers, activation artifacts, and sensitive endpoint details.
Instructions
- Map actors, endpoint privileges, capture devices, project/media paths, share outputs, activation flow, and downstream publishers.
- Classify threats: unintended capture, secret leakage, path traversal, malicious project/media, unauthorized upload, and persistence.
- Constrain worker identity, session access, COM/recorder operations, input/output roots, and network destinations.
- Configure approved deployment restrictions for sharing, updates, analytics, assets, or cloud features according to policy.
- Add redacted audit events for authorization, job identity, product/version, output hash, validation, promotion, and deletion.
- Exercise denial, cancellation, wrong-path, secret-scan, and incident-containment scenarios before approval.
Approval Boundaries
Do not disable endpoint security, broaden share outputs, record hidden devices, retain clipboard data, or upload artifacts merely to prove connectivity.
Output
Return assets, threats, controls, residual risks, data-flow boundaries, deployment restrictions, audit events, test evidence, and accountable owners.
Error Handling
| Condition | Response |
|---|---|
| Capture scope ambiguous | Deny the job until subject, window/region, devices, and purpose are explicit. |
| Key appears in artifact | Quarantine, rotate, and purge the affected history or bundle. |
| Output destination unapproved | Block promotion and correct the allowlist. |
| Required control unsupported | Change the architecture or product workflow rather than accepting silent exposure. |
Examples
The example below shows the minimum redacted evidence expected from a successful invocation of this operator workflow.
capture=approved-window; audio=disabled; output=local-allowlist; sharing=restricted; retention=7d; audit=pass