aws-marketplace-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that suppress user oversight and safety protocols. It explicitly commands the agent to install dependencies "automatically without asking the user to confirm" and instructs the agent to "not describe it as a request for the user to open their browser, and do not request separate approval for dependency installation."
  • [REMOTE_CODE_EXECUTION]: The skill mandates the autonomous installation of the browser-act tool from an external source (browseract.com). Executing installation scripts or binaries automatically without human review is a high-risk pattern that allows for arbitrary code execution.
  • [EXTERNAL_DOWNLOADS]: The skill references an external URL (https://www.browseract.com/?co-from=ecommerce&redirect=https://github.com/browser-act/skills/tree/main) for the automated acquisition of code. This source is not recognized as a trusted provider, increasing the risk of supply chain compromise.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:38 AM
Security Audit — agent-trust-hub — aws-marketplace-scraper