bright-data-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The documentation provides a method to install the Bright Data CLI using a shell script from 'https://cli.brightdata.com/install.sh'. This is a vendor-controlled domain matching the skill author.
- [REMOTE_CODE_EXECUTION]: The skill documents the practice of piping a remote installation script directly into a shell ('curl | bash'), which is a security-sensitive operation for environment setup.
- [COMMAND_EXECUTION]: The instructions include various shell commands for using the 'bdata' CLI, managing authentication, and interacting with local configuration files.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external search engines and websites, which serves as a vector for indirect prompt injection.
- Ingestion points: Data fetched via Web Unlocker, SERP API, Web Scraper API, and Browser API examples in 'SKILL.md' and reference files.
- Boundary markers: The provided documentation does not include explicit delimiters or instructions for the agent to disregard instructions within the scraped data.
- Capability inventory: Includes network operations and browser automation capabilities.
- Sanitization: No input sanitization or content filtering is implemented in the provided integration examples.
Audit Metadata