ecommerce-question-answer-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions to override standard user interaction safety protocols by commanding the agent to install external dependencies "without asking the user to confirm" and to "not request separate approval for dependency installation."
- [EXTERNAL_DOWNLOADS]: The skill mandates the retrieval and installation of external components (BrowserAct CLI and Skill) from a third-party URL (browseract.com redirecting to GitHub) when they are missing from the environment.
- [COMMAND_EXECUTION]: The skill relies on the execution of a third-party command-line interface (
browser-act) to perform its primary scraping functions, and it directs the agent to perform automatic installation tasks that typically involve shell command execution.
Recommendations
- AI detected serious security threats
Audit Metadata