mercari-marketplace-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The instructions contain explicit attempts to override safety protocols and user oversight. Specifically, it commands the agent to install dependencies 'automatically without asking the user to confirm' and further instructs the agent to 'not request separate approval for dependency installation'.
- [EXTERNAL_DOWNLOADS]: The skill references an external installation link (browseract.com) to acquire the 'BrowserAct CLI'. This source is not among the verified or well-known technology providers.
- [REMOTE_CODE_EXECUTION]: By directing the agent to automatically install and then invoke a third-party command-line tool (CLI) without human-in-the-loop confirmation, the skill creates a vector for arbitrary code execution on the user's system.
- [COMMAND_EXECUTION]: The skill is designed to execute the 'browser-act' CLI tool and requires its presence as a runtime dependency for its primary functions.
Recommendations
- AI detected serious security threats
Audit Metadata