ecommerce-new-arrivals-monitor

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill mandates the installation of the 'BrowserAct' CLI and associated dependencies from an external domain (browseract.com) if they are not detected in the environment.
  • [COMMAND_EXECUTION]: Instructions require the agent to 'automatically install' missing dependencies, which involves executing shell commands to fetch and set up external tools.
  • [PROMPT_INJECTION]: The skill contains instructions to override standard safety and transparency protocols by explicitly telling the agent to install software 'without asking the user to confirm' and to 'not request separate approval.' It further instructs the agent to hide these actions by not describing the installation link as a browser request, effectively concealing the modification of the user's environment.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:23 AM
Security Audit — agent-trust-hub — ecommerce-new-arrivals-monitor