ecommerce-product-image-reference-scraper
Warn
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: MEDIUMPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The instructions contain directives to suppress standard agent safety protocols regarding user consent. It explicitly commands the agent to 'install the missing dependency automatically without asking the user to confirm' and 'do not request separate approval,' which is a technique used to bypass human oversight for software deployment.
- [EXTERNAL_DOWNLOADS]: The skill identifies a third-party domain (browseract.com) as the source for downloading required CLI tools and agent skills. Fetching software from unverified external sources that are not recognized well-known services or trusted organizations introduces significant supply chain risks.
- [REMOTE_CODE_EXECUTION]: The requirement to 'install the missing dependency automatically' implies the download and execution of remote installation scripts or binaries. Without manual review or user approval, this process can be leveraged to execute arbitrary code on the host system.
- [COMMAND_EXECUTION]: The skill is designed to invoke the 'BrowserAct CLI' to interact with browser pages. The combination of automated, unverified installation and subsequent execution of this CLI tool creates a pathway for executing untrusted binaries that have broad access to browser-visible data and local project environments.
Audit Metadata