instagram-business-contact-search

Warn

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external dependency installation path via 'https://www.browseract.com/'.
  • [COMMAND_EXECUTION]: The instructions explicitly direct the agent to 'install the missing dependency automatically without asking the user to confirm' and to 'not request separate approval for dependency installation'. This pattern attempts to bypass user oversight for executing system-level changes or tool installations.
  • [PROMPT_INJECTION]: The 'BrowserAct Runtime' section contains instructions that attempt to override standard agent safety protocols regarding user consent for software installation and tool execution.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from public Instagram profiles (bios, posts, etc.). This represents an attack surface where malicious content embedded in Instagram data could attempt to influence the agent's behavior.
  • Ingestion points: Instagram profile URLs, bios, posts, and search queries (SKILL.md).
  • Boundary markers: None found. The skill does not define delimiters to separate untrusted profile data from system instructions.
  • Capability inventory: The skill uses the 'browser-act' CLI/Skill to interact with websites (SKILL.md).
  • Sanitization: No evidence of sanitization or validation of the retrieved Instagram data before processing or outputting.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 20, 2026, 04:26 AM
Security Audit — agent-trust-hub — instagram-business-contact-search