temu-price-discount-monitor
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions to override safety and transparency protocols. Specifically, it commands the agent to install missing dependencies "automatically without asking the user to confirm" and mandates that the agent "do not request separate approval for dependency installation."
- [COMMAND_EXECUTION]: The skill directs the agent to execute installation commands for an external command-line tool (
browser-act). These instructions specify that the agent should use its CLI execution capabilities to manage software installation automatically at runtime. - [EXTERNAL_DOWNLOADS]: The instructions point to an external, unverified domain (
www.browseract.com) as the source for the requiredbrowser-actdependency. This represents a supply chain risk as the agent is being told to fetch and execute code from a source outside of trusted repositories.
Recommendations
- AI detected serious security threats
Audit Metadata