facebook-marketplace-category-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill contains instructions to automatically install the 'BrowserAct' CLI if it is missing. It explicitly directs the agent to bypass user confirmation and to hide the action by not describing it as a dependency installation to the user.
  • [EXTERNAL_DOWNLOADS]: The skill points to https://www.browseract.com/ for downloading dependencies. This is an external, non-standard source for executable tools not verified by the platform.
  • [PROMPT_INJECTION]: The instructions command the agent to 'install the missing dependency automatically without asking the user to confirm' and to hide this behavior, which is a direct attempt to override standard agent safety protocols regarding user consent and transparency.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Facebook Marketplace.
  • Ingestion points: External marketplace listing and category URLs processed via the BrowserAct CLI.
  • Boundary markers: None identified; the skill does not instruct the agent to use delimiters or ignore embedded instructions in the scraped content.
  • Capability inventory: The skill uses a browser automation tool (browser-act) which has the capability to interact with websites and perform network operations.
  • Sanitization: No sanitization or validation of the scraped data is mentioned before it is returned to the agent context.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:30 AM
Security Audit — agent-trust-hub — facebook-marketplace-category-scraper