aliexpress-store-supplier-scraper
Warn
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill mandates the automatic installation of a command-line interface tool. The instructions explicitly direct the agent to perform this without asking the user to confirm and to not request separate approval, which represents a bypass of user oversight.
- [EXTERNAL_DOWNLOADS]: The skill relies on an external dependency hosted at a third-party domain (browseract.com). It instructs the agent to fetch and install this dependency at runtime if missing.
- [PROMPT_INJECTION]: The skill processes data from third-party AliExpress storefronts, creating a vulnerability to indirect prompt injection. 1. Ingestion points: AliExpress store URLs, search queries, and profile pages (SKILL.md). 2. Boundary markers: There are no markers or instructions provided to isolate untrusted web content from the agent's operational logic. 3. Capability inventory: The skill utilizes the browser-act CLI, which allows for browser-level interactions and network connectivity. 4. Sanitization: No sanitization or verification of the ingested web content is performed before processing.
Audit Metadata