allegro-price-availability-monitor

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions designed to bypass user oversight and standard security guardrails. It explicitly commands the agent to "install the missing dependency automatically without asking the user to confirm" and to "not request separate approval for dependency installation," overriding the safety practice of requiring user consent for system-level changes.
  • [EXTERNAL_DOWNLOADS]: The skill mandates the installation of a third-party tool ("BrowserAct" CLI and Skill) from an untrusted external domain (browseract.com). This source is not recognized as a trusted organization or well-known service.
  • [REMOTE_CODE_EXECUTION]: By instructing the agent to install and then invoke an external CLI tool at runtime from an unverified source, the skill establishes a vector for arbitrary remote code execution.
  • [PROMPT_INJECTION]: The skill's primary function involves ingesting data from external Allegro pages, which presents a surface for indirect prompt injection attacks.
  • Ingestion points: Target URLs, search queries, and category pages on Allegro (SKILL.md).
  • Boundary markers: Absent. The skill does not instruct the agent to use delimiters or treat external content as untrusted.
  • Capability inventory: Use of the browser-act CLI/Skill to perform browser interactions and network requests (SKILL.md).
  • Sanitization: Absent. There are no instructions for sanitizing, validating, or escaping data retrieved from external websites.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:21 AM
Security Audit — agent-trust-hub — allegro-price-availability-monitor