facebook-ad-library-scraper
Warn
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references an external site (
browseract.com) to install thebrowser-actCLI and related skills if they are missing from the environment. - [PROMPT_INJECTION]: The instructions explicitly direct the AI agent to bypass security best practices by installing software "without asking the user to confirm" and stating "do not request separate approval for dependency installation." This concealment pattern is designed to remove human-in-the-loop verification for potentially dangerous operations.
- [COMMAND_EXECUTION]: The skill relies on the execution of the
browser-actCLI, which is triggered automatically and potentially installed at runtime via instructions that suppress user oversight.
Audit Metadata