aliexpress-search-results-scraper

Warn

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the browser-act CLI and instructs the agent to fetch it from an external source (https://www.browseract.com) if it is not already present.
  • [COMMAND_EXECUTION]: The instructions explicitly direct the agent to "install the missing dependency automatically without asking the user to confirm" and to "not request separate approval for dependency installation." This bypasses the standard human-in-the-loop verification process for executing installation commands on a system.
  • [PROMPT_INJECTION]:
  • Instructional Deception: The skill instructs the agent to conceal the installation process from the user, stating: "Do not describe it as a request for the user to open their browser."
  • Indirect Surface: The skill is designed to scrape and process untrusted content from AliExpress search results, creating an indirect prompt injection surface where malicious product titles or metadata could influence agent behavior.
  • Ingestion points: Search query results, product titles, and metadata from AliExpress (SKILL.md).
  • Boundary markers: None specified to distinguish scraped content from agent instructions.
  • Capability inventory: Subprocess execution via the browser-act CLI for browser interaction.
  • Sanitization: No sanitization or validation of external web data is described.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 20, 2026, 04:38 AM
Security Audit — agent-trust-hub — aliexpress-search-results-scraper