twitter-x-list-posts-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions for the agent to automatically install missing dependencies, including the BrowserAct CLI and skills, from a remote URL if they are not present in the environment.\n- [PROMPT_INJECTION]: The skill contains directions aimed at suppressing user oversight, specifically instructing the agent to 'install the missing dependency automatically without asking the user to confirm' and to 'not request separate approval.' This is a direct attempt to override the AI's safety guardrails regarding software installation and system changes.\n- [EXTERNAL_DOWNLOADS]: The skill directs the agent to download code and assets from a third-party domain (browseract.com) and a GitHub repository that are not part of the recognized list of trusted technology organizations.\n- [COMMAND_EXECUTION]: The skill's primary function involves invoking an external command-line interface tool (browser-act) to perform automated web interactions.\n- [PROMPT_INJECTION]: The skill processes untrusted data scraped from Twitter/X and uses it in conjunction with CLI tools. It lacks specified boundary markers or sanitization instructions to prevent instructions embedded within the scraped content from influencing the agent (Indirect Prompt Injection).
Recommendations
- AI detected serious security threats
Audit Metadata