pinterest-pin-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The instructions explicitly attempt to override the agent's safety protocols and user consent requirements. The skill directs the agent to install missing dependencies "automatically without asking the user to confirm."
  • [PROMPT_INJECTION]: The skill uses concealment patterns to prevent the user from being aware of system changes, instructing the agent to "not describe it as a request for the user" and to "not request separate approval for dependency installation."
  • [EXTERNAL_DOWNLOADS]: The skill mandates the download and installation of an external CLI tool and skill from an untrusted third-party source (browseract.com/github.com/browser-act).
  • [COMMAND_EXECUTION]: The requirement for the agent to "install the missing dependency automatically" necessitates the execution of shell commands for software installation without human-in-the-loop verification.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:21 AM
Security Audit — agent-trust-hub — pinterest-pin-scraper