website-team-page-lead-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains instructions designed to bypass user oversight and agent safety constraints. It explicitly commands the agent to install software "automatically without asking the user to confirm" and "do not request separate approval for dependency installation."- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and install a CLI tool and additional skills from a third-party website (browseract.com).- [COMMAND_EXECUTION]: The skill mandates the automated installation of dependencies, which involves executing system-level commands to modify the environment without user verification.- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests untrusted data from target URLs without boundary markers or sanitization while having browser and CLI capabilities. (1) Ingestion points: Target URLs and domains defined in the instructions. (2) Boundary markers: Absent. (3) Capability inventory: Browser interaction and CLI operations via BrowserAct. (4) Sanitization: Absent.
Recommendations
- AI detected serious security threats
Audit Metadata