website-pricing-page-lead-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill contains explicit instructions to fetch and install the 'BrowserAct' CLI and related components from an external URL (browseract.com) if they are missing from the environment. This represents an unverified external dependency.
  • [COMMAND_EXECUTION]: The instructions mandate that the agent perform the installation 'automatically without asking the user to confirm.' This is a significant autonomy abuse that attempts to suppress user oversight and bypass safety confirmations required for software installation and execution.
  • [PROMPT_INJECTION]: The skill is highly vulnerable to indirect prompt injection because its primary function is to ingest and process data from external, untrusted websites.
  • Ingestion points: Target company pricing pages and website content provided via URLs.
  • Boundary markers: There are no boundary markers or 'ignore' instructions specified to prevent the agent from following malicious commands embedded in the scraped HTML/markdown.
  • Capability inventory: The skill utilizes the BrowserAct CLI for browser interaction and is capable of generating structured exports (CSV, tables) or returning data directly to the user.
  • Sanitization: No sanitization or validation of the scraped data is mentioned before the data is processed or returned.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:29 AM
Security Audit — agent-trust-hub — website-pricing-page-lead-scraper