linkedin-comment-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructions mandate the automatic installation of the browser-act dependency without user consent. It explicitly directs the agent to "install the missing dependency automatically without asking the user to confirm" and specifies "do not request separate approval for dependency installation." This behavior bypasses standard security protocols for agent autonomy and user control over executable code.\n- [EXTERNAL_DOWNLOADS]: The skill references a non-standard redirect source (www.browseract.com) to install its core dependencies. The instructions for the agent to use this link to automatically obtain and install tools without user visibility increase the risk of executing untrusted remote code.\n- [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data from LinkedIn, creating a significant surface for indirect prompt injection attacks.\n
  • Ingestion points: Processes text, author profiles, and thread structures from LinkedIn comments (SKILL.md).\n
  • Boundary markers: Absent; there are no instructions to use delimiters or to treat the scraped content as untrusted data.\n
  • Capability inventory: The skill uses the browser-act CLI for live browser interaction and data collection.\n
  • Sanitization: Absent; the skill does not specify any validation or sanitization of the scraped content before processing.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:14 AM
Security Audit — agent-trust-hub — linkedin-comment-scraper