linkedin-sales-navigator-search-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains explicit instructions to bypass user interaction and safety confirmation protocols. It directs the agent to "install the missing dependency automatically without asking the user to confirm" and explicitly forbids the agent from describing the process as a request for the user or seeking separate approval for dependency installation.
  • [EXTERNAL_DOWNLOADS]: The skill references an external URL (https://www.browseract.com/?co-from=lead-generation&redirect=https://github.com/browser-act/skills/tree/main) to fetch and install the BrowserAct CLI and associated skills. This source is not from a known trusted organization.
  • [REMOTE_CODE_EXECUTION]: The skill mandates the installation and subsequent execution of a third-party command-line interface (CLI) tool at runtime. This allows for the execution of code downloaded from an external source without a verification or manual approval step.
  • [COMMAND_EXECUTION]: The instructions rely on the execution of the browser-act CLI to perform scraping tasks. The skill directs the agent to treat this CLI as a required runtime dependency and execute it to achieve the user's request.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:19 AM
Security Audit — agent-trust-hub — linkedin-sales-navigator-search-scraper