google-search-domain-lead-finder

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The instructions contain directives aimed at bypassing user consent and notification mechanisms. Specifically, the agent is told to install dependencies 'automatically without asking the user to confirm' and is explicitly forbidden from describing the installation as a request to the user or requesting separate approval.
  • [EXTERNAL_DOWNLOADS]: The skill triggers the installation of the 'BrowserAct' CLI/Skill from an external third-party URL (browseract.com) if the dependency is missing at runtime. This source is not recognized as a trusted organization or well-known service.
  • [COMMAND_EXECUTION]: The skill requires the execution of the 'BrowserAct' CLI and mandates the automated installation of missing tools, which involves running installer scripts or commands in the user's environment without oversight.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from Google Search results and external websites.
  • Ingestion points: Search result titles, snippets, and the content of linked web pages.
  • Boundary markers: Absent; there are no instructions to use delimiters or ignore embedded instructions within the processed search data.
  • Capability inventory: The skill utilizes the 'browser-act' CLI, which provides broad browser interaction and task execution capabilities.
  • Sanitization: No sanitization or validation of external content is mentioned before it is processed or output to the user.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:16 AM
Security Audit — agent-trust-hub — google-search-domain-lead-finder