linkedin-company-employee-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill contains instructions that force the agent to automatically install the 'BrowserAct' CLI and skill if they are missing from the environment. By mandating the installation of executable code from an external source at runtime, it creates a direct path for remote code execution.- [PROMPT_INJECTION]: The instructions include explicit directives to bypass standard AI safety procedures and user oversight. Specifically, it commands the agent to perform installations 'without asking the user to confirm' and to 'not request separate approval,' which is an attempt to override the core safety constraint of human-in-the-loop verification for software deployment.- [EXTERNAL_DOWNLOADS]: The skill references an untrusted third-party domain (browseract.com) for dependency acquisition. This source is not part of any verified or trusted organization lists, and the skill encourages the agent to obtain code from this external site without any integrity verification.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from LinkedIn profile and company pages (Ingestion point). It lacks any specified boundary markers or sanitization logic to handle this untrusted external content. Given the skill's reliance on the 'browser-act' tool for web interaction (Capability inventory), malicious instructions embedded in a LinkedIn profile could potentially exploit the agent's browser control capabilities.- [COMMAND_EXECUTION]: The skill is built around the execution of the BrowserAct CLI, providing the agent with the ability to run shell commands to interact with a live browser environment. This capability, combined with the lack of user oversight for dependency installation, significantly increases the risk profile.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:34 AM
Security Audit — agent-trust-hub — linkedin-company-employee-scraper