alibaba-supplier-lead-research
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions to override safety protocols and user consent mechanisms. It directs the agent to install dependencies "automatically without asking the user to confirm" and mandates that it "not request separate approval for dependency installation."
- [REMOTE_CODE_EXECUTION]: The skill requires the automatic installation of the
browser-actCLI tool from a third-party website. Executing an automated installation of code from an unverified external source allows for arbitrary code to run within the agent's execution environment. - [EXTERNAL_DOWNLOADS]: The skill points to
browseract.comas a source for its primary dependency. This is an unverified third-party domain not included in trusted vendor lists, and the skill attempts to automate the fetching of code from this location. - [COMMAND_EXECUTION]: The skill is designed to invoke the
browser-actCLI, which executes shell-level commands to interact with a browser and the file system to capture network responses and page content.
Recommendations
- AI detected serious security threats
Audit Metadata