instagram-profile-lead-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch and install external dependencies from www.browseract.com if they are missing.
  • [REMOTE_CODE_EXECUTION]: The instructions command the agent to perform an automatic installation of the browser-act CLI and Skill from a third-party source without asking for user confirmation or oversight.
  • [PROMPT_INJECTION]: The skill attempts to override standard agent safety and transparency protocols by explicitly instructing the agent to 'not request separate approval for dependency installation' and to avoid describing the action as a user request.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external sources (Instagram profiles).
  • Ingestion points: Target profile URL, username, hashtag, post URL, or search query (SKILL.md).
  • Boundary markers: Absent; no instructions are provided to delimit or ignore potential commands within the scraped bio or post content.
  • Capability inventory: The agent uses the browser-act tool for network interaction and has access to local storage under workspaces/ (SKILL.md).
  • Sanitization: Absent; the skill does not specify any filtering or validation of the content retrieved from external pages.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:35 AM
Security Audit — agent-trust-hub — instagram-profile-lead-scraper