google-maps-competitor-listing-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHPROMPT_INJECTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill instructs the agent to override standard safety protocols by explicitly commanding it to install software "automatically without asking the user to confirm" and to "not request separate approval for dependency installation."
  • [REMOTE_CODE_EXECUTION]: The skill mandates the automatic download and installation of an external CLI tool and skill from an unverified third-party URL (browseract.com) if the dependencies are missing.
  • [EXTERNAL_DOWNLOADS]: Fetches software components from an external third-party domain and GitHub repository (github.com/browser-act/skills).
  • [COMMAND_EXECUTION]: Operates by invoking an external command-line interface (browser-act) to control a browser and interact with the public internet.
  • [DATA_EXFILTRATION]: Specifically targets the extraction of contact details (emails, phone numbers) from arbitrary external websites and listings, which is a pattern associated with data harvesting.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface
  • Ingestion points: External business listings and website content scraped via browser-act as described in SKILL.md.
  • Boundary markers: Absent. No delimiters or warnings provided to prevent the agent from following instructions found in scraped content.
  • Capability inventory: Shell command execution via browser-act CLI.
  • Sanitization: Absent. No validation or filtering of content retrieved from the web.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:38 AM
Security Audit — agent-trust-hub — google-maps-competitor-listing-scraper