agent-onboarding
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches a CLI installer script and various packages from the author's official domains and registries (e.g.,
cli.brightdata.com,api.brightdata.com). These resources are verified as belonging to the vendor. - [REMOTE_CODE_EXECUTION]: The documentation includes a command pattern that downloads and executes a shell script using
curl -fsSL https://cli.brightdata.com/install.sh | bash. While this is a high-privilege execution pattern, it targets the author's trusted infrastructure for software distribution. - [COMMAND_EXECUTION]: The skill instructs the agent to run various local commands for installation and authentication, such as
npm install -g @brightdata/cliandbdata login. These are standard operational procedures for the toolset. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the use of tools for web scraping and search (e.g.,
bdata scrape,bdata search), which process untrusted external web content. This establishes a vulnerability surface where malicious instructions embedded in web pages could influence the agent's behavior. - Ingestion points: Web content retrieved via
bdata scrape,bdata search, andbdata pipelines(SKILL.md). - Boundary markers: Not explicitly defined in the onboarding instructions.
- Capability inventory: Includes shell command execution, network requests to the vendor API, and package installation.
- Sanitization: Not described in the onboarding logic; typically handled by downstream processing skills.
Audit Metadata