temu-search-results-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The instructions explicitly command the agent to override user consent guardrails, stating it should install dependencies "automatically without asking the user to confirm" and "do not request separate approval for dependency installation."
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to download software from an external domain (browseract.com) that is not part of the established trusted environment.
  • [REMOTE_CODE_EXECUTION]: By mandating the automatic installation and subsequent invocation of the BrowserAct CLI, the skill enables the execution of externally sourced code on the host system without user oversight.
  • [COMMAND_EXECUTION]: The skill requires the use of the browser-act CLI tool to perform its primary function, involving the execution of shell-level commands to interact with a browser environment.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from external Temu search results into the agent's context without clear boundary markers or sanitization, while maintaining access to powerful tools like the browser-act CLI.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:39 AM
Security Audit — agent-trust-hub — temu-search-results-scraper