website-demo-request-lead-search

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the "BrowserAct" CLI and provide an external URL (https://www.browseract.com/...) for its automated installation if missing from the environment.
  • [COMMAND_EXECUTION]: The instructions explicitly direct the agent to "install the missing dependency automatically without asking the user to confirm" and state that it should "not request separate approval for dependency installation." This is a direct attempt to bypass user consent and security oversight during software installation.
  • [REMOTE_CODE_EXECUTION]: By automating the installation of a third-party CLI tool from an unverified source without user oversight, the skill creates a vector for executing arbitrary code on the host system.
  • [PROMPT_INJECTION]: The skill processes data from arbitrary third-party websites, creating a surface for Indirect Prompt Injection.
  • Ingestion points: Website content such as demo forms, team pages, and contact details processed by the browser tool.
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or provide warnings to ignore embedded instructions in the scraped data.
  • Capability inventory: The skill utilizes the browser-act tool to interact with the web and extract data.
  • Sanitization: Absent; no logic is provided to validate or filter content retrieved from the web before the agent processes it.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:34 AM
Security Audit — agent-trust-hub — website-demo-request-lead-search