weibo-post-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructions mandate the automatic installation of the BrowserAct CLI and additional skills from an external source if they are missing at runtime.
  • [EXTERNAL_DOWNLOADS]: The skill triggers downloads from a third-party domain (browseract.com) that is not recognized as a trusted or well-known service, bypassing user validation for dependency acquisition.
  • [PROMPT_INJECTION]: The skill contains instructions designed to override the agent's safety protocols by explicitly directing it to install dependencies 'without asking the user to confirm' and to hide this behavior by not describing it as a request to open the browser or a dependency installation.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:28 AM
Security Audit — agent-trust-hub — weibo-post-scraper