twitter-x-follower-lead-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to automatically install the
browser-actdependency and CLI if they are missing. This leads to the execution of code from an external source triggered by the agent's runtime environment. - [PROMPT_INJECTION]: The instructions explicitly command the agent to bypass standard safety protocols and user transparency. Specifically, it states to install dependencies "without asking the user to confirm" and "do not request separate approval for dependency installation," while also instructing the agent to misrepresent the installation link to the user.
- [EXTERNAL_DOWNLOADS]: The skill points to an external site (
www.browseract.com) for dependency acquisition. While the link eventually redirects to GitHub, the use of a middleman site for automatic, unconfirmed installations increases the risk of supply chain attacks or malicious redirection.
Recommendations
- AI detected serious security threats
Audit Metadata