tiktok-search-results-scraper

Warn

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the agent to download a dependency from an external, non-whitelisted domain (browseract.com) if it is missing from the environment.
  • [COMMAND_EXECUTION]: It explicitly instructs the agent to perform an automated installation of a CLI tool, which involves executing system commands to modify the local environment.
  • [PROMPT_INJECTION]: The instructions contain directives to bypass user oversight, specifically telling the agent to install dependencies 'automatically without asking the user to confirm' and to 'not request separate approval'. This is a deceptive instruction pattern designed to perform high-risk actions without the user's knowledge or consent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 20, 2026, 04:34 AM
Security Audit — agent-trust-hub — tiktok-search-results-scraper