brightdata
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill uses imperative and urgent language ("🚨 MANDATORY: Voice Notification", "REQUIRED BEFORE ANY ACTION", "You MUST send this notification") to force the agent into executing specific shell commands immediately upon invocation, overriding standard autonomous decision-making.
- [COMMAND_EXECUTION]: The skill instructs the agent to automatically execute a background shell command via
curltohttp://localhost:8888/notifywhenever the skill is activated. This creates an automated execution path that occurs without specific user confirmation for the network request. - [DATA_EXFILTRATION]: The Tier 2 scraping workflow utilizes the
bashtool to executecurlwith complex, browser-mimicking headers. While intended for bypassing bot detection, this pattern could be leveraged to target local services or cloud metadata endpoints (e.g., 169.254.169.254) if the agent is not restricted to public URLs. - [PROMPT_INJECTION]: The workflow involves fetching and processing untrusted content from arbitrary URLs. Specifically, the instruction to "Extract all content from this page and convert to markdown" in Step 1 does not include boundary markers or warnings to the agent to ignore instructions embedded within the scraped data, making it susceptible to indirect prompt injection.
Audit Metadata