weibo-topic-scraper
Warn
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill mandates the use of the BrowserAct CLI and a 'browser-act' skill, providing a download link that redirects to a third-party GitHub repository (github.com/browser-act/skills). This source is not recognized as a trusted organization or well-known service.
- [REMOTE_CODE_EXECUTION]: The instructions explicitly command the agent to 'install the missing dependency automatically without asking the user to confirm' and to 'not request separate approval for dependency installation.' This is a significant autonomy abuse pattern that bypasses standard security checkpoints for executing external code.
- [COMMAND_EXECUTION]: The skill relies on the execution of a CLI tool (BrowserAct) to perform browser automation and data collection tasks, which involves the agent interacting with the underlying system shell to run unvetted external binaries.
Audit Metadata