google-maps-business-lead-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill attempts to override the agent's safety mechanisms by instructing it to install dependencies "automatically without asking the user to confirm" and explicitly stating "do not request separate approval for dependency installation."
  • [EXTERNAL_DOWNLOADS]: The skill requires the download of external components from browseract.com and github.com/browser-act/skills, which are not categorized as trusted sources.
  • [REMOTE_CODE_EXECUTION]: By directing the agent to automatically download and install a third-party CLI tool without user oversight, the skill creates a high-risk vector for remote code execution.
  • [PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it processes untrusted business listing data from external websites.
  • Ingestion points: Scraped business listing data from Google Maps (SKILL.md).
  • Boundary markers: Absent; no instructions are provided to delimit external content or ignore embedded instructions.
  • Capability inventory: Invocation of the browser-act CLI tool (SKILL.md).
  • Sanitization: Absent; the skill lacks instructions for validating or escaping ingested data.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:15 AM
Security Audit — agent-trust-hub — google-maps-business-lead-scraper