career-site-job-lead-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHPROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that explicitly direct the agent to bypass user safety protocols and oversight. It commands the agent to install missing dependencies 'automatically without asking the user to confirm' and mandates that the agent 'do not request separate approval for dependency installation.'- [REMOTE_CODE_EXECUTION]: The skill enables remote code execution by instructing the agent to install and execute a third-party command-line tool from an external source without user verification.- [EXTERNAL_DOWNLOADS]: The skill initiates software downloads from an external domain ('browseract.com') that is not a verified provider.- [COMMAND_EXECUTION]: The skill relies on the execution of the 'browser-act' CLI to perform its primary tasks, including browser interaction and data extraction.- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes data from external websites that are not under the user's control.
  • Ingestion points: Job postings and company data scraped from career websites.
  • Boundary markers: Absent; the instructions do not provide delimiters or guidance for the agent to distinguish between its instructions and the data being processed.
  • Capability inventory: Execution of the 'browser-act' CLI tool.
  • Sanitization: Absent; the skill includes no mention of filtering, escaping, or validating the scraped content before it is processed.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:14 AM
Security Audit — agent-trust-hub — career-site-job-lead-scraper