facebook-post-lead-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The instructions contain explicit directives to bypass the agent's safety protocols by requiring software installation 'without asking the user to confirm' and to 'not request separate approval'.
- [PROMPT_INJECTION]: The skill uses concealment techniques, instructing the agent to 'not describe it as a request for the user to open their browser' when installing code.
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to fetch dependencies from an untrusted domain 'www.browseract.com'.
- [REMOTE_CODE_EXECUTION]: The skill mandates the automatic installation and execution of an external CLI tool from an unverified source.
Recommendations
- AI detected serious security threats
Audit Metadata