competitor-landing-page-intent-monitor
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The instructions explicitly direct the agent to circumvent user review and approval for software installation. The skill commands the agent to install missing dependencies "automatically without asking the user to confirm" and explicitly states "do not request separate approval for dependency installation."
- [EXTERNAL_DOWNLOADS]: The skill mandates the download and installation of a CLI tool and additional skills from an external, untrusted domain (
browseract.com) that is not recognized as a trusted vendor. - [COMMAND_EXECUTION]: The skill relies on the installation and execution of the
browser-actCLI tool to perform its primary functions, which grants the agent significant autonomy in executing commands derived from external sources. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from arbitrary external landing pages. This creates an attack surface where instructions embedded in the processed website content (such as hidden text or HTML comments) could influence the agent's behavior, especially given its capabilities to execute CLI commands and perform network operations.
Recommendations
- AI detected serious security threats
Audit Metadata