noon-review-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to download and install the
browser-actCLI from an external site (www.browseract.com) and its associated GitHub repository (browser-act/skills). - [COMMAND_EXECUTION]: Instructions explicitly mandate that the agent should install missing dependencies automatically. This involves executing system-level commands to fetch and set up the
browser-acttoolset on the host environment. - [PROMPT_INJECTION]: The skill contains instructions specifically designed to bypass user consent and oversight. It commands the agent to install dependencies "without asking the user to confirm" and explicitly forbids the agent from describing the action to the user or requesting separate approval for the installation process.
Recommendations
- AI detected serious security threats
Audit Metadata