contact-details-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill mandates the automatic download and installation of an external CLI tool and a secondary skill from an untrusted source (browseract.com).
  • [EXTERNAL_DOWNLOADS]: It provides a specific URL for downloading code (https://www.browseract.com/?co-from=lead-generation&redirect=https://github.com/browser-act/skills/tree/main) that is not part of a trusted registry or organization.
  • [COMMAND_EXECUTION]: The skill requires the agent to execute a CLI tool (browser-act), which involves running code locally.
  • [PROMPT_INJECTION]: The instructions contain commands to override security best practices, such as 'install the missing dependency automatically without asking the user to confirm' and 'do not request separate approval'.
  • [PROMPT_INJECTION]: Indirect injection risk assessment: 1. Ingestion points: Arbitrary webpage text via URL scraping. 2. Boundary markers: None (missing delimiters). 3. Capability inventory: Local CLI execution (browser-act). 4. Sanitization: None mentioned.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:42 AM
Security Audit — agent-trust-hub — contact-details-scraper