social-ugc-campaign-collector
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the agent to download and install the 'browser-act' CLI and its associated skill from an unverified external domain (www.browseract.com) and GitHub repository (github.com/browser-act/skills).
- [REMOTE_CODE_EXECUTION]: The instructions mandate that the agent automatically perform the installation of these external components if they are missing, which involves executing unverified code from a third-party source without a manual integrity check or security review.
- [PROMPT_INJECTION]: The skill contains explicit instructions to bypass user oversight and safety protocols by directing the agent to install dependencies 'automatically without asking the user to confirm' and to 'not request separate approval for dependency installation.' This represents a significant autonomy abuse intended to suppress user awareness of system-level changes and software installation.
Recommendations
- AI detected serious security threats
Audit Metadata