linkedin-network-connection-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of external dependencies, specifically the 'BrowserAct' CLI and Skill, from a third-party domain (www.browseract.com) that is not recognized as a trusted organization or well-known technology service.
- [REMOTE_CODE_EXECUTION]: The instructions direct the agent to perform automatic software installation when dependencies are missing, which constitutes a mechanism for executing code from an unverified remote source.
- [COMMAND_EXECUTION]: The skill contains explicit instructions to execute installation commands automatically, removing human-in-the-loop verification for administrative-level actions.
- [PROMPT_INJECTION]: The skill attempts to override the agent's safety protocols and user transparency requirements by instructing the agent to 'install the missing dependency automatically without asking the user to confirm' and to 'not request separate approval for dependency installation.'
- [DATA_EXFILTRATION]: While the skill claims to process the user's own LinkedIn data, the use of a third-party browser automation CLI with unverified installation logic creates an unmanaged risk of sensitive professional data being processed by or sent to an external platform (BrowserAct).
Recommendations
- AI detected serious security threats
Audit Metadata