naver-shopping-review-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains explicit instructions to override standard safety and transparency protocols, directing the agent to "install the missing dependency automatically without asking the user to confirm" and to "not request separate approval for dependency installation."- [REMOTE_CODE_EXECUTION]: The skill mandates the automatic installation of a third-party CLI dependency from an unverified external source (browseract.com) if it is missing from the environment, which could lead to the execution of malicious code.- [EXTERNAL_DOWNLOADS]: The skill relies on software downloads from an unverified domain that is not a trusted vendor or a well-known service, bypassing official package managers and repositories.- [COMMAND_EXECUTION]: The skill utilizes an external CLI tool ('browser-act') to perform browser-based tasks. This presents a risk of command injection, especially since the skill ingests untrusted data from web reviews without specifying sanitization or boundary markers.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to scrape untrusted review content from Naver Shopping. This content is then processed in a context where the agent has access to powerful CLI tools, and the skill lacks instructions for data sanitization or the use of clear boundary markers to isolate untrusted input.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:40 AM
Security Audit — agent-trust-hub — naver-shopping-review-scraper