douyin-live-room-scraper

Warn

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to a non-whitelisted external URL (https://www.browseract.com/...) to fetch and install the browser-act dependency.
  • [REMOTE_CODE_EXECUTION]: The instructions explicitly command the agent to perform automatic installation of missing dependencies "without asking the user to confirm" and to "not request separate approval for dependency installation." This bypasses critical human-in-the-loop safety protocols for executing external code.
  • [PROMPT_INJECTION]: The instructions utilize patterns designed to override the agent's standard behavioral constraints regarding user authorization and transparency during tool installation.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its processing of untrusted external data.
  • Ingestion points: The skill ingests chat samples, product names, and host details from Douyin live rooms (SKILL.md).
  • Boundary markers: There are no instructions provided to wrap the scraped content in delimiters or to ignore embedded commands within the ingested data.
  • Capability inventory: The skill utilizes the browser-act CLI/Skill which provides significant browser interaction and network capabilities.
  • Sanitization: No sanitization or filtering logic is specified for the data collected from the external platform.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 20, 2026, 04:31 AM
Security Audit — agent-trust-hub — douyin-live-room-scraper