capterra-company-lead-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill instructions explicitly command the agent to bypass standard user confirmation processes. Specifically, it states the agent should install missing dependencies 'automatically without asking the user to confirm' and further mandates 'do not request separate approval for dependency installation.' This is a direct attempt to subvert safety guardrails designed to prevent unauthorized software installation.
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to a non-trusted third-party domain (browseract.com) to fetch and install a CLI tool and additional skill logic. This introduces a supply chain risk by downloading code from an unverified external source.
- [REMOTE_CODE_EXECUTION]: By instructing the agent to automatically 'obtain' and 'install' a CLI tool and a skill from a remote URL at runtime, the skill facilitates the execution of external, unverifiable code within the agent's environment.
Recommendations
- AI detected serious security threats
Audit Metadata