1688-search-results-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHPROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill instructions explicitly direct the agent to bypass standard safety confirmations. It instructs the agent to install dependencies "automatically without asking the user to confirm" and further emphasizes "do not request separate approval for dependency installation."
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of a CLI tool from an unverified external source (browseract.com and a related GitHub repository). These sources are not recognized as trusted or well-known vendors.
- [REMOTE_CODE_EXECUTION]: By mandating the automatic installation of an external CLI tool at runtime, the skill facilitates the execution of unverified remote code on the system without human oversight.
Recommendations
- AI detected serious security threats
Audit Metadata