etsy-keyword-research

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to override standard safety protocols by performing software installations without user consent. It explicitly commands the agent to "install the missing dependency automatically without asking the user to confirm" and "do not request separate approval for dependency installation."
  • [REMOTE_CODE_EXECUTION]: The skill mandates the automatic download and installation of an external CLI tool (BrowserAct) and additional agent skills from a remote source. This behavior, combined with the instruction to bypass user oversight, creates a significant risk of unauthorized code execution on the host system as the agent is directed to autonomously execute installation routines.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:36 AM
Security Audit — agent-trust-hub — etsy-keyword-research