noon-price-availability-monitor

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the agent to fetch an external CLI tool and additional skills from a non-trusted third-party domain (browseract.com).
  • [REMOTE_CODE_EXECUTION]: The instructions explicitly command the agent to install these dependencies "automatically without asking the user to confirm" and further direct the agent to "not request separate approval for dependency installation," which removes the user's ability to vet external code before it runs.
  • [DATA_EXFILTRATION]: The skill directs the agent to capture "browser-visible network responses," which may expose sensitive information like session cookies, authentication headers, or private API data from the user's browser session.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted content from external web pages. Ingestion points: Noon.com product, search, and category pages (SKILL.md). Boundary markers: None (absent). Capability inventory: Browser interaction and execution via the browser-act skill and CLI (SKILL.md). Sanitization: None (absent).
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:30 AM
Security Audit — agent-trust-hub — noon-price-availability-monitor