data-feeds
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands using the
bdataCLI tool along with standard utilities likejq,xargs, andbashto automate data extraction pipelines and verify output integrity. - [EXTERNAL_DOWNLOADS]: The skill directs users to install and authenticate the Bright Data CLI (
bdata), which is a vendor-provided tool required for the skill's primary functionality. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources (such as Amazon, LinkedIn, and TikTok), which presents a risk of indirect prompt injection.
- Ingestion points: Data is retrieved from external URLs via
bdata pipelinesand stored in local JSON or NDJSON files (e.g.,product.json,posts.ndjson) to be read by the agent. - Boundary markers: The instructions do not utilize specific delimiters or boundary markers to differentiate between extracted data and agent instructions.
- Capability inventory: The skill performs shell command execution, file system writes, and network operations (via the CLI tool).
- Sanitization: The skill incorporates verification steps using
jqto ensure valid JSON structure and check for error fields, but it does not perform content-based sanitization of the extracted data.
Audit Metadata