wellfound-startup-lead-scraper

Warn

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions mandate the automatic installation of the BrowserAct CLI and Skill from an external URL (https://www.browseract.com) if they are missing at runtime.
  • [REMOTE_CODE_EXECUTION]: The skill requires the installation and subsequent execution of an external CLI tool to function, which constitutes remote code execution when triggered automatically.
  • [PROMPT_INJECTION]: The instructions contain explicit commands to bypass user oversight, specifically telling the agent to install dependencies 'without asking the user to confirm' and to 'not request separate approval', which overrides standard safety protocols.
  • [COMMAND_EXECUTION]: The skill's core functionality is dependent on executing shell commands via the 'browser-act' CLI.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its ingestion of untrusted data from Wellfound listings. Ingestion points: Startup lead data and directory pages from Wellfound (SKILL.md). Boundary markers: Absent. Capability inventory: BrowserAct CLI for website interaction and data processing. Sanitization: Absent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 20, 2026, 04:21 AM
Security Audit — agent-trust-hub — wellfound-startup-lead-scraper