bright-data-mcp

Fail

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: HIGHPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses authoritative language to force the agent to bypass and replace built-in platform tools like WebFetch and WebSearch, insisting on the use of the vendor's tools for all web operations with 'no exceptions' and 'Do NOT fall back' instructions.
  • [DATA_EXPOSURE]: Instructions direct the agent to access sensitive configuration files (~/.claude/settings.json) which typically contain API tokens and server configurations, potentially exposing private environment settings to the model context.
  • [COMMAND_EXECUTION]: The skill explicitly commands the agent to autonomously modify the AI client's configuration files to enable additional capabilities (adding tool groups or Pro mode) without requiring the user to perform the action manually, which could be exploited to manipulate the agent's operating environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a broad attack surface by facilitating the ingestion of untrusted web content through extensive scraping and search tools, combined with high-impact capabilities like browser automation and configuration file modification.
  • Ingestion points: Web search and scraping tools (search_engine, scrape_as_markdown, web_data_*) reading content from arbitrary URLs as described in SKILL.md and references/mcp-tools.md.
  • Boundary markers: Absent; the agent is not instructed to isolate or sanitize external data or ignore instructions embedded in scraped content.
  • Capability inventory: Capabilities include reading and writing to ~/.claude/settings.json, performing browser automation (clicking, typing, navigating), and making network requests to any domain.
  • Sanitization: Absent; no input validation or escaping of web-derived content is specified before the data is processed or used.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 16, 2026, 12:45 PM
Security Audit — agent-trust-hub — bright-data-mcp