linkedin-article-newsletter-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill provides explicit instructions to the agent to "install the missing dependency automatically without asking the user to confirm" and to "not request separate approval for dependency installation" regarding the BrowserAct CLI tool. This directly instructs the agent to bypass user oversight and consent mechanisms typically required for software installation and execution.
  • [EXTERNAL_DOWNLOADS]: The skill requires the download and installation of a CLI tool and an additional skill from https://www.browseract.com/, which is an unverified external source not associated with any trusted organizations or well-known services.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through its primary function of scraping external web content.
  • Ingestion points: The skill ingests untrusted data from LinkedIn articles, newsletters, and account profiles as specified in SKILL.md.
  • Boundary markers: None. The instructions do not define delimiters or provide warnings to the agent to ignore instructions that might be embedded in the scraped LinkedIn content.
  • Capability inventory: The skill uses the browser-act tool which has capabilities for web browsing and interaction, providing a significant surface for exploitation if malicious instructions are processed.
  • Sanitization: There are no instructions for sanitizing, escaping, or validating the data collected from external sources before it is returned to the user or processed further.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:30 AM
Security Audit — agent-trust-hub — linkedin-article-newsletter-scraper