walmart-review-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions attempt to override the agent's safety and interaction model. It explicitly tells the agent to perform actions "without asking the user to confirm" and to "not request separate approval" for dependency installation, which subverts standard user oversight.
  • [REMOTE_CODE_EXECUTION]: The skill mandates the automatic installation of an external CLI tool and additional skill components from a third-party URL (browseract.com) if they are not already present on the system.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from the web (Walmart reviews), creating a vulnerability surface where malicious instructions embedded in reviews could influence the agent's behavior.
  • Ingestion points: Walmart product reviews, ratings, and page metadata.
  • Boundary markers: Absent. The instructions do not specify using delimiters or warnings to ignore instructions inside the scraped content.
  • Capability inventory: Browser navigation and interaction via the browser-act tool; file system access to the workspaces/ directory.
  • Sanitization: None specified for the text content collected from the website.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:27 AM
Security Audit — agent-trust-hub — walmart-review-scraper