scraper-studio

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's primary function is to execute the bdata CLI tool to manage web scrapers. This includes creating templates (bdata scraper create), running extraction jobs (bdata scraper run), and modifying existing scrapers (bdata scraper heal). These operations are consistent with the skill's stated purpose of providing a terminal interface for Bright Data services.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data by scraping external URLs provided by the user.\n
  • Ingestion points: The bdata scraper run command (found in SKILL.md and references/recipes.md) takes a URL as input, which is then processed by the Bright Data service.\n
  • Boundary markers: The instructions and examples do not define explicit boundary markers or instructions to ignore embedded content within the target pages.\n
  • Capability inventory: The skill has the capability to execute shell commands (bdata, jq) and write data to the local filesystem using the -o or --input-file flags.\n
  • Sanitization: The skill relies on the Bright Data AI Flow backend to safely interpret page content and extract data according to the defined schema without executing malicious instructions found on the page.\n- [DYNAMIC_EXECUTION]: A recipe in references/recipes.md demonstrates using eval to execute a command string (next_step) parsed from a JSON file. This JSON file is generated by the bdata scraper approve command. This pattern is used to automate the transition from approving a scraper fix to verifying it with a new run, effectively executing a command suggested by the vendor's own CLI tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:45 PM
Security Audit — agent-trust-hub — scraper-studio