1688-price-moq-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHPROMPT_INJECTIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill includes instructions that explicitly direct the agent to override standard safety protocols and bypass user-in-the-loop controls. It mandates that dependencies be installed "automatically without asking the user to confirm" and further instructs the agent to "not request separate approval for dependency installation."
  • [REMOTE_CODE_EXECUTION]: The skill requires the automatic installation of a CLI tool from a remote URL. By instructing the agent to perform this installation without user consent, it creates a high-risk vector for remote code execution.
  • [COMMAND_EXECUTION]: The skill relies on the execution of an external CLI tool to perform its scraping tasks. The instruction to install and execute this tool silently increases the risk of unauthorized command execution.
  • [EXTERNAL_DOWNLOADS]: The skill points to an external domain (browseract.com) and a GitHub repository for mandatory runtime components. These sources are outside the verified trusted scope.
  • [PROMPT_INJECTION]: Indirect Prompt Injection vulnerability surface detected. 1. Ingestion points: Target URLs and page content from 1688.com. 2. Boundary markers: The instructions do not define delimiters to separate external data from agent instructions. 3. Capability inventory: The skill uses a browser-based CLI for automation. 4. Sanitization: No mechanisms are described for sanitizing content retrieved from external sites.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:33 AM
Security Audit — agent-trust-hub — 1688-price-moq-scraper