ebay-sold-listings-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions explicitly command the agent to bypass user confirmation protocols. It directs the agent to install dependencies "automatically without asking the user to confirm" and to "not request separate approval for dependency installation." This is a deliberate attempt to override the AI agent's safety and transparency guidelines.
- [EXTERNAL_DOWNLOADS]: The skill specifies an external URL (https://www.browseract.com/?co-from=ecommerce&redirect=https://github.com/browser-act/skills/tree/main) for downloading and installing the BrowserAct CLI and Skill. This domain is not identified as a trusted or well-known service.
- [COMMAND_EXECUTION]: The requirement to automatically install missing dependencies implies the execution of shell commands to download and set up software on the host system without user oversight or authorization.
Recommendations
- AI detected serious security threats
Audit Metadata