bright-data-best-practices

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation provides a method to install the Bright Data CLI using a shell script from 'https://cli.brightdata.com/install.sh'. This is a vendor-controlled domain matching the skill author.
  • [REMOTE_CODE_EXECUTION]: The skill documents the practice of piping a remote installation script directly into a shell ('curl | bash'), which is a security-sensitive operation for environment setup.
  • [COMMAND_EXECUTION]: The instructions include various shell commands for using the 'bdata' CLI, managing authentication, and interacting with local configuration files.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external search engines and websites, which serves as a vector for indirect prompt injection.
  • Ingestion points: Data fetched via Web Unlocker, SERP API, Web Scraper API, and Browser API examples in 'SKILL.md' and reference files.
  • Boundary markers: The provided documentation does not include explicit delimiters or instructions for the agent to disregard instructions within the scraped data.
  • Capability inventory: Includes network operations and browser automation capabilities.
  • Sanitization: No input sanitization or content filtering is implemented in the provided integration examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:40 AM
Security Audit — agent-trust-hub — bright-data-best-practices