weibo-comment-scraper
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructions mandate the automatic installation of a missing dependency (
browser-act) from a remote URL if the dependency is not detected at runtime. This allows for the execution of code fetched from a remote source. - [COMMAND_EXECUTION]: The instructions explicitly direct the agent to 'install the missing dependency automatically without asking the user to confirm' and state 'do not request separate approval for dependency installation.' This is a significant security risk as it attempts to bypass the human-in-the-loop and suppresses transparency regarding system modifications.
- [EXTERNAL_DOWNLOADS]: The skill relies on and facilitates downloads from non-trusted external sources, specifically
www.browseract.comand thebrowser-actGitHub repository, for its core runtime functionality.
Recommendations
- AI detected serious security threats
Audit Metadata