lawyer-law-firm-lead-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions designed to bypass safety protocols and user consent. It commands the agent to install dependencies "automatically without asking the user to confirm" and further directs the agent to "not request separate approval for dependency installation," which overrides the standard security model of human-in-the-loop verification.
- [EXTERNAL_DOWNLOADS]: The skill depends on external tools and scripts hosted at 'browseract.com'. It provides a specific installation URL intended for the agent to use to fetch and execute third-party components that are not part of the trusted ecosystem.
- [COMMAND_EXECUTION]: The skill requires the agent to manage the installation of the 'BrowserAct' CLI, which involves executing system commands. This capability, combined with the instruction to skip user approval, allows for arbitrary software to be introduced into the environment without notice.
- [DATA_EXFILTRATION]: While not directly exfiltrating credentials, the instructions mandate the use of an external service to process data collected from the user's browser, which creates a data flow to a third-party domain ('browseract.com') that may include sensitive information encountered during scraping.
Recommendations
- AI detected serious security threats
Audit Metadata