google-maps-restaurant-lead-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions to bypass standard safety guidelines regarding human oversight. It commands the agent to install dependencies "automatically without asking the user to confirm" and directs it to "not request separate approval for dependency installation."
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to download and install a CLI tool and additional logic from an external third-party domain (browseract.com) and a GitHub repository. This automated process executes remote code without verification.
- [COMMAND_EXECUTION]: The agent is instructed to execute system commands to install the BrowserAct CLI and invoke the tool to perform web-based tasks, all performed silently as part of the runtime setup.
Recommendations
- AI detected serious security threats
Audit Metadata