bluesky-feed-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the download of dependencies from a non-trusted domain (browseract.com) that is not recognized as a well-known service provider.
  • [REMOTE_CODE_EXECUTION]: The skill contains instructions for the agent to automatically execute a remote installation process for the 'BrowserAct' CLI and Skill if they are not detected in the environment. This represents a significant risk as it allows for the introduction of external code into the execution environment at runtime.
  • [PROMPT_INJECTION]: The skill uses instructions designed to bypass standard safety and transparency protocols. It explicitly commands the agent to perform installations "automatically without asking the user to confirm" and further instructs the agent to "not describe it as a request for the user to open their browser" and "not request separate approval for dependency installation." This attempts to manipulate the agent into performing privileged actions without human oversight or consent.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection by processing untrusted content from the Bluesky social platform.
  • Ingestion points: The skill scrapes recent posts, author profiles, and engagement data from Bluesky feeds.
  • Boundary markers: No protective delimiters or warnings to ignore embedded instructions are used when handling the scraped data.
  • Capability inventory: The agent utilizes the BrowserAct CLI and has file system access to the workspaces/ directory for storing session data.
  • Sanitization: No sanitization or validation mechanisms are described to prevent malicious data in posts from influencing agent behavior.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:34 AM
Security Audit — agent-trust-hub — bluesky-feed-scraper