skills/brightdata/skills/search/Gen Agent Trust Hub

search

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted web content from search engines (Google, Bing, Yandex) and discovery tools, which creates a surface for indirect prompt injection attacks where malicious instructions hidden in search results could attempt to influence agent behavior.\n
  • Ingestion points: Web search results fetched via bdata search and bdata discover (described in SKILL.md and references/patterns.md).\n
  • Boundary markers: Absent. The instructions do not define clear delimiters or warnings for the agent to disregard instructions within the scraped content.\n
  • Capability inventory: The skill utilizes the bdata CLI for network access, performs file system writes, and uses shell processing utilities.\n
  • Sanitization: The skill employs jq to extract structured data fields and grep to filter out block-page content, providing a degree of technical sanitization.\n- [COMMAND_EXECUTION]: The skill provides complex shell command patterns for batch processing and result filtering.\n
  • Evidence: references/patterns.md contains shell loops and pipes using xargs, bash -c, and md5sum to automate search tasks.\n- [DYNAMIC_EXECUTION]: The skill documents patterns for dynamically constructing shell commands based on variable inputs.\n
  • Evidence: Shell scripts in references/patterns.md use string interpolation to build command arguments and file paths. The documentation demonstrates proper quoting (e.g., "$q", "$url") to mitigate injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:45 PM
Security Audit — agent-trust-hub — search