lazada-seller-profile-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to automatically download and install external dependencies from a third-party URL (https://www.browseract.com/...) if they are missing from the environment.
  • [COMMAND_EXECUTION]: The skill mandates the bypass of user oversight by explicitly instructing the agent to perform installation "automatically without asking the user to confirm" and to "not request separate approval for dependency installation". This is a severe autonomy abuse that removes the human-in-the-loop safety requirement for software installation.
  • [PROMPT_INJECTION]: The skill is vulnerable to Indirect Prompt Injection as it processes untrusted data from external Lazada seller profiles without proper sanitization or boundary markers.
  • Ingestion points: Scraped seller profiles, ratings, and reviews from Lazada (SKILL.md, Instructions step 5).
  • Boundary markers: Absent. The skill provides no delimiters or instructions to the agent to ignore commands embedded within the scraped content.
  • Capability inventory: The skill utilizes the browser-act CLI and Skill which possess network and browser interaction capabilities.
  • Sanitization: Absent. There are no instructions to validate or filter the content retrieved from the marketplace.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:21 AM
Security Audit — agent-trust-hub — lazada-seller-profile-scraper