twitter-x-search-results-lead-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructions require the agent to automatically install the 'BrowserAct CLI' dependency if it is found to be missing. It provides a specific URL (browseract.com) to facilitate this installation.
- [PROMPT_INJECTION]: The skill contains explicit instructions to override the agent's standard safety procedures regarding user consent. It commands the agent to install dependencies 'automatically without asking the user to confirm' and 'do not request separate approval for dependency installation.' This is a direct attempt to subvert the 'human-in-the-loop' security model.
- [EXTERNAL_DOWNLOADS]: The skill points to an external domain (browseract.com) for downloading and installing required runtime components. This domain is not a recognized trusted vendor or well-known development service.
- [COMMAND_EXECUTION]: The skill relies on the execution of a Command Line Interface (CLI) tool ('browser-act') to perform its tasks, which involves the invocation of shell processes.
Recommendations
- AI detected serious security threats
Audit Metadata