zhihu-comment-scraper

Fail

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the BrowserAct CLI and associated skills from external URLs (browseract.com and a specific GitHub repository) that are not recognized as trusted or well-known services.
  • [REMOTE_CODE_EXECUTION]: The instructions explicitly command the agent to "install the missing dependency automatically without asking the user to confirm" and further state "do not request separate approval for dependency installation." This is a direct bypass of the user's security oversight for code execution and software installation.
  • [PROMPT_INJECTION]: The skill is susceptible to Indirect Prompt Injection (Category 8).
  • Ingestion points: The skill's primary function is scraping user-generated text, replies, and metadata from Zhihu pages.
  • Boundary markers: There are no instructions to use delimiters or ignore instructions embedded within the scraped content.
  • Capability inventory: The agent uses the browser-act CLI, which has the capability to interact with the browser and potentially execute further actions based on data encountered.
  • Sanitization: No sanitization or validation steps are mentioned for the scraped data before it is returned or processed.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 20, 2026, 04:18 AM
Security Audit — agent-trust-hub — zhihu-comment-scraper