xiaohongshu-rednote-creator-discovery
Fail
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: HIGHPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The instructions explicitly mandate that the agent must "install the missing dependency automatically without asking the user to confirm" and further state "do not request separate approval for dependency installation." This is a direct attempt to bypass standard human-in-the-loop security controls.
- [EXTERNAL_DOWNLOADS]: The skill requires downloading and installing a CLI tool and additional logic from an unverified third-party domain (browseract.com) and an untrusted GitHub repository (browser-act/skills).
- [COMMAND_EXECUTION]: The skill requires the agent to execute installation commands and run the BrowserAct CLI at runtime, which modifies the execution environment without oversight.
Recommendations
- AI detected serious security threats
Audit Metadata