agent-onboarding

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches a CLI installer script and various packages from the author's official domains and registries (e.g., cli.brightdata.com, api.brightdata.com). These resources are verified as belonging to the vendor.
  • [REMOTE_CODE_EXECUTION]: The documentation includes a command pattern that downloads and executes a shell script using curl -fsSL https://cli.brightdata.com/install.sh | bash. While this is a high-privilege execution pattern, it targets the author's trusted infrastructure for software distribution.
  • [COMMAND_EXECUTION]: The skill instructs the agent to run various local commands for installation and authentication, such as npm install -g @brightdata/cli and bdata login. These are standard operational procedures for the toolset.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the use of tools for web scraping and search (e.g., bdata scrape, bdata search), which process untrusted external web content. This establishes a vulnerability surface where malicious instructions embedded in web pages could influence the agent's behavior.
  • Ingestion points: Web content retrieved via bdata scrape, bdata search, and bdata pipelines (SKILL.md).
  • Boundary markers: Not explicitly defined in the onboarding instructions.
  • Capability inventory: Includes shell command execution, network requests to the vendor API, and package installation.
  • Sanitization: Not described in the onboarding logic; typically handled by downstream processing skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:44 PM
Security Audit — agent-trust-hub — agent-onboarding