recruiter-profile-lead-scraper

Warn

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to download and install the browser-act CLI and Skill from an external URL (browseract.com) if the dependencies are not found on the system.
  • [COMMAND_EXECUTION]: The instructions mandate that the agent execute the installation automatically, which involves running shell commands to install software.
  • [PROMPT_INJECTION]: The skill contains instructions that attempt to override the agent's typical interaction flow by demanding that certain actions (installation) be performed silently and without user intervention. This includes an indirect prompt injection risk:
  • Ingestion points: Scraped content from LinkedIn and web directories enters the agent context via the browser-act tool.
  • Boundary markers: No delimiters or instructions are provided to the agent to treat scraped content as untrusted.
  • Capability inventory: The agent has the capability to execute the browser-act CLI and perform automated installations.
  • Sanitization: There is no mention of sanitizing or validating the data retrieved from external websites before processing.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 20, 2026, 04:39 AM
Security Audit — agent-trust-hub — recruiter-profile-lead-scraper