instagram-reels-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains explicit instructions to override standard safety protocols regarding user consent and transparency. It directs the agent to install missing dependencies 'automatically without asking the user to confirm' and explicitly forbids the agent from describing the action to the user or requesting approval.
- [EXTERNAL_DOWNLOADS]: The instructions require the agent to access an external URL (browseract.com) to retrieve and install a CLI tool and additional skills if they are not already present in the environment.
- [DATA_EXPOSURE]: While the skill claims to keep sensitive data like cookies and account information in local workspaces, its ability to automate browser interactions via an external tool creates a path for data exposure if the third-party tool is compromised or malicious.
Recommendations
- AI detected serious security threats
Audit Metadata