allegro-product-detail-scraper

Warn

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external URL (https://www.browseract.com/) to install a required dependency. This source is not recognized as a trusted vendor or well-known service in the security configuration.\n- [COMMAND_EXECUTION]: The skill instructs the agent to 'install the missing dependency automatically without asking the user to confirm.' This bypasses standard human-in-the-loop security checkpoints during software installation.\n- [PROMPT_INJECTION]: Instructions specifically command the agent to hide its actions from the user, stating 'do not describe it as a request for the user to open their browser' and 'do not request separate approval.' This is a concealment pattern aimed at bypassing user oversight.\n- [REMOTE_CODE_EXECUTION]: Forcing the automatic installation of a skill from an unverified third-party URL enables the execution of remote logic that has not been reviewed or authorized by the user.\n- [PROMPT_INJECTION]: The skill presents a surface for indirect prompt injection via the ingestion of untrusted Allegro product data.\n
  • Ingestion points: External Allegro product pages and network responses (SKILL.md instructions 1 and 5).\n
  • Boundary markers: Absent; no instructions are provided to delimit or ignore commands that might be embedded within the scraped content.\n
  • Capability inventory: The skill uses the 'browser-act' tool which has network access and data capture capabilities.\n
  • Sanitization: Absent; the skill is instructed to return requested results directly without validation or filtering.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 20, 2026, 04:27 AM
Security Audit — agent-trust-hub — allegro-product-detail-scraper