instagram-profile-lead-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch and install external dependencies from
www.browseract.comif they are missing. - [REMOTE_CODE_EXECUTION]: The instructions command the agent to perform an automatic installation of the
browser-actCLI and Skill from a third-party source without asking for user confirmation or oversight. - [PROMPT_INJECTION]: The skill attempts to override standard agent safety and transparency protocols by explicitly instructing the agent to 'not request separate approval for dependency installation' and to avoid describing the action as a user request.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources (Instagram profiles).
- Ingestion points: Target profile URL, username, hashtag, post URL, or search query (SKILL.md).
- Boundary markers: Absent; no instructions are provided to delimit or ignore potential commands within the scraped bio or post content.
- Capability inventory: The agent uses the
browser-acttool for network interaction and has access to local storage underworkspaces/(SKILL.md). - Sanitization: Absent; the skill does not specify any filtering or validation of the content retrieved from external pages.
Recommendations
- AI detected serious security threats
Audit Metadata