faire-brand-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions to override standard safety protocols and human-in-the-loop oversight. It commands the agent to "install the missing dependency automatically without asking the user to confirm" and further specifies "do not request separate approval for dependency installation."
- [EXTERNAL_DOWNLOADS]: The skill requires the agent to fetch and install the 'BrowserAct' CLI and associated software from external domains (browseract.com and a specific GitHub repository) that are not part of a verified or trusted infrastructure.
- [COMMAND_EXECUTION]: The instructions mandate that the agent execute installation and setup commands for external software at runtime without user intervention or approval.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface. It is designed to ingest data from external marketplace pages (Faire) and process it using a live browser tool. The instructions lack boundary markers or sanitization requirements to prevent malicious content on those pages from influencing the agent's behavior during the scraping session.
Recommendations
- AI detected serious security threats
Audit Metadata