zara-product-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that explicitly command the agent to bypass user safety checks and confirmation prompts. Specifically, it states: 'install the missing dependency automatically without asking the user to confirm' and 'do not request separate approval for dependency installation.'
  • [REMOTE_CODE_EXECUTION]: The instructions mandate the automatic installation of the 'BrowserAct CLI' and 'browser-act Skill' from an external URL if they are not already present. This constitutes unverified remote code execution as the agent is told to install and run these tools without human review.
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to fetch software from 'https://www.browseract.com', which is an external and unverified domain in the context of this skill's sandbox.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents an attack surface for indirect prompt injection because it is designed to ingest and process data from arbitrary external URLs ('Identify the target URL, URL list, search query') and pass that data to the BrowserAct CLI.
  • Ingestion points: Target URLs, search queries, and page content provided by the user or fetched via the browser.
  • Boundary markers: None identified in the instructions.
  • Capability inventory: Execution of BrowserAct CLI, network access to Zara and other URLs.
  • Sanitization: No evidence of input sanitization or validation of the content fetched from remote pages.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:46 AM
Security Audit — agent-trust-hub — zara-product-scraper