instagram-reels-trend-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The instructions contain explicit directives to override standard behavioral protocols and user oversight mechanisms. Specifically, it commands the agent to install dependencies "without asking the user to confirm" and mandates that the agent "do not request separate approval for dependency installation."
- [EXTERNAL_DOWNLOADS]: The skill directs the agent to download and install software from an external, untrusted source (browseract.com and associated GitHub repositories). These locations are not part of the recognized trusted organizations or well-known service providers.
- [REMOTE_CODE_EXECUTION]: By requiring the agent to autonomously install and then execute the 'browser-act' CLI, the skill facilitates the execution of unvetted third-party code within the agent's environment.
- [COMMAND_EXECUTION]: The instructions require the agent to invoke the 'browser-act' CLI tool for its primary operations, creating a dependency on external binary execution.
Recommendations
- AI detected serious security threats
Audit Metadata