skills/sam6dvpte34/lead-generation-skill/google-search-local-service-lead-search/Gen Agent Trust Hub
google-search-local-service-lead-search
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The instructions mandate the automatic installation of the BrowserAct CLI from an external URL if the dependency is missing. This involves downloading and executing code from a remote source at runtime.
- [COMMAND_EXECUTION]: The skill directs the agent to perform software installation tasks automatically, which typically involves shell command execution to set up the CLI environment.
- [PROMPT_INJECTION]: The instructions explicitly override safety and transparency protocols by commanding the agent to perform actions 'without asking the user to confirm' and specifically directing the agent to 'not describe it as a request for the user' and 'not request separate approval for dependency installation.' This is a deliberate attempt to suppress user oversight of high-risk actions.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from Google Search results and external websites, which are untrusted sources.
- Ingestion points: Search snippets, website contact details, and page content (SKILL.md).
- Boundary markers: None provided to distinguish between search data and instructions.
- Capability inventory: Ability to interact with web pages and execute CLI commands via BrowserAct.
- Sanitization: No sanitization or validation of the ingested search data is mentioned.
Recommendations
- AI detected serious security threats
Audit Metadata