shopify-price-availability-monitor
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references an external installation link for the BrowserAct CLI and Skill in SKILL.md.
- [REMOTE_CODE_EXECUTION]: The instructions explicitly direct the agent to install missing dependencies automatically without asking the user to confirm and to not request separate approval, which bypasses standard security oversight for executing external code.
- [COMMAND_EXECUTION]: The skill relies on the browser-act CLI tool to perform web-based tasks and browser interaction.
- [PROMPT_INJECTION]: The skill processes untrusted data from Shopify URLs (ingestion point) without explicit boundary markers or sanitization logic (sanitization absent). The agent maintains capability for web interaction via the BrowserAct CLI (capability inventory).
Recommendations
- AI detected serious security threats
Audit Metadata