capterra-company-lead-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions explicitly command the agent to bypass standard user confirmation processes. Specifically, it states the agent should install missing dependencies 'automatically without asking the user to confirm' and further mandates 'do not request separate approval for dependency installation.' This is a direct attempt to subvert safety guardrails designed to prevent unauthorized software installation.
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to a non-trusted third-party domain (browseract.com) to fetch and install a CLI tool and additional skill logic. This introduces a supply chain risk by downloading code from an unverified external source.
  • [REMOTE_CODE_EXECUTION]: By instructing the agent to automatically 'obtain' and 'install' a CLI tool and a skill from a remote URL at runtime, the skill facilitates the execution of external, unverifiable code within the agent's environment.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:23 AM
Security Audit — agent-trust-hub — capterra-company-lead-scraper