twitter-x-following-list-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides a link to an external website (browseract.com) and instructs the agent to use it to install missing dependencies automatically.
  • [REMOTE_CODE_EXECUTION]: The instructions mandate the installation and execution of an external CLI tool ('BrowserAct') and a corresponding agent skill from an unverified third-party source.
  • [COMMAND_EXECUTION]: The skill requires the agent to run the browser-act CLI, which introduces the risk of executing arbitrary code provided by an external vendor.
  • [PROMPT_INJECTION]: The skill contains instructions that attempt to override standard security practices by directing the agent to install software 'automatically without asking the user to confirm' and explicitly telling the agent 'do not request separate approval for dependency installation'. This is a form of autonomy abuse intended to bypass human-in-the-loop safety constraints.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:46 AM
Security Audit — agent-trust-hub — twitter-x-following-list-scraper