reddit-search-results-lead-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions to override the agent's standard behavior regarding user confirmation. Specifically, it tells the agent to install dependencies 'automatically without asking the user to confirm' and 'do not request separate approval for dependency installation'. This attempts to bypass the safety principle of human-in-the-loop for software installation.
- [COMMAND_EXECUTION]: The instructions mandate the execution of installation commands for the 'BrowserAct CLI' and associated skills. This represents a capability to modify the system environment autonomously.
- [EXTERNAL_DOWNLOADS]: The skill relies on external resources from 'browseract.com' and 'github.com/browser-act' for its runtime. It provides a specific URL for the agent to fetch and install software, which is not part of a verified or trusted vendor list.
- [DATA_EXFILTRATION]: While the primary purpose is 'lead scraping' (data collection), the instructions to scrape personal profile details (karma score, account age, contact signals) from Reddit and store them in
workspaces/creates an inherent risk of large-scale data harvesting.
Recommendations
- AI detected serious security threats
Audit Metadata