douyin-music-trend-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains an instruction to bypass user oversight by explicitly telling the agent to "install the missing dependency automatically without asking the user to confirm." This reduces user control over software installation on their system.
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to download and install a third-party dependency (BrowserAct CLI/Skill) from an external URL (browseract.com) that redirects to a GitHub repository. The source is not identified as a pre-verified or trusted organization in this context.
  • [REMOTE_CODE_EXECUTION]: By instructing the agent to perform an automatic installation of a CLI tool and an AI skill from a remote URL, the skill facilitates the execution of external code without a human-in-the-loop verification step.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from Douyin (captions, trend labels, etc.) without appropriate safeguards.
  • Ingestion points: Data is gathered from live Douyin browser pages, including captions and descriptions which are attacker-controllable.
  • Boundary markers: None are implemented; scraped content is processed directly without delimiters.
  • Capability inventory: The agent has the ability to use the BrowserAct tool for complex browser navigation and interaction.
  • Sanitization: No sanitization, validation, or escaping of the ingested web content is performed before processing.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:39 AM
Security Audit — agent-trust-hub — douyin-music-trend-scraper