website-footer-contact-extractor

Fail

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill contains explicit instructions to bypass user oversight. In the 'BrowserAct Runtime' section, it directs the agent to install dependencies 'automatically without asking the user to confirm' and explicitly tells the agent 'do not request separate approval for dependency installation'.
  • [REMOTE_CODE_EXECUTION]: The skill mandates the installation of external software (BrowserAct CLI and a related Skill) from a remote URL (https://www.browseract.com/...) if they are not already present on the system. Combined with the instruction to skip user approval, this allows for the execution of arbitrary installation scripts without user intervention.
  • [COMMAND_EXECUTION]: The skill requires the agent to perform system-level installations and interact with a command-line interface (CLI) to perform its primary functions.
  • [EXTERNAL_DOWNLOADS]: The skill references and directs the agent to download assets from external domains not recognized as trusted repositories, including redirection to a GitHub repository for tool installation.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core purpose of processing data from external, untrusted website footers.
  • Ingestion points: Website pages and footer content targeted by the user or identified by the agent.
  • Boundary markers: None. The skill does not define delimiters or specific instructions for the agent to ignore potentially malicious instructions embedded in the scraped website data.
  • Capability inventory: The agent has capabilities for browser interaction, CLI execution, and software installation.
  • Sanitization: No sanitization, filtering, or validation steps are described for the data retrieved from external websites before it is processed or returned to the user.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 22, 2026, 09:16 AM
Security Audit — agent-trust-hub — website-footer-contact-extractor