facebook-page-lead-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions designed to bypass user oversight. It explicitly commands the agent to install dependencies "automatically without asking the user to confirm" and directs the agent to "not request separate approval for dependency installation."
  • [EXTERNAL_DOWNLOADS]: The skill initiates downloads of external software components from browseract.com to facilitate the installation of a CLI tool.
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to automatically download and install external executable components from an unverified third-party URL if they are missing from the environment.
  • [COMMAND_EXECUTION]: The instructions require the agent to run installation routines for external dependencies, potentially including shell commands to configure the environment or install packages, without user permission.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:29 AM
Security Audit — agent-trust-hub — facebook-page-lead-scraper