brightdata-cli
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides instructions for installing the Bright Data CLI via a shell script downloaded from the official vendor domain and piped to the shell (
curl -fsSL https://cli.brightdata.com/install.sh | bash). This is a standard installation procedure for the vendor's software. - [EXTERNAL_DOWNLOADS]: The skill references and facilitates the installation of the official Bright Data CLI package through the Node Package Manager (
@brightdata/cli). - [INDIRECT_PROMPT_INJECTION]: The skill's primary functionality involves ingesting data from external URLs, search engine results, and social media platforms into the agent's context. This creates a surface where instructions embedded in external web content could potentially influence the agent's behavior.
- Ingestion points: Content is retrieved through commands like
bdata scrape,bdata search, andbdata pipelinesfrom arbitrary user-provided or search-discovered URLs. - Boundary markers: The instructions do not define specific delimiters or "ignore previous instructions" safety markers for the agent when it processes the resulting markdown or HTML data.
- Capability inventory: The CLI possesses capabilities to perform network requests, write data to local files via the
-oflag, and manage account-level proxy configurations. - Sanitization: No explicit sanitization or filtering of the scraped content is mentioned before the data is presented to the agent.
Audit Metadata