Back to skill

Security audit

Bright-Data-MCP-Claude-Skill-deep-research

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for Bright Data web research, but it needs review because it encourages broad automated scraping, third-party processing, and logged-in browser sessions without enough upfront user controls.

Install this only if you intentionally want Bright Data-powered automated web scraping. Before using it, confirm that target sites and data are permitted to be scraped, avoid private, logged-in, internal, regulated, or personal-data sources unless you have explicit authorization, and assume submitted URLs and extracted page content may be handled by an external provider. Keep batches and automation conservative and review site terms, robots.txt, rate limits, and retention needs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level activation description is broad enough to match generic requests like 'search and analyze web content' or 'perform market research,' which may trigger this scraping-capable skill in contexts where simpler or safer approaches would suffice. Overbroad routing increases the likelihood of unnecessary web scraping, browser automation, and external data collection beyond user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill promotes advanced web research, anti-bot protection, browser automation, and large-scale collection, but its warnings are limited and buried later under best practices. Without a prominent upfront warning about legal restrictions, privacy concerns, terms-of-service issues, and server impact, users may be guided into risky or non-compliant scraping behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The applicability section lists broad categories such as market research, competitive analysis, and large-scale web data gathering without clear guardrails or exclusion criteria. In practice, this can cause the skill to activate for ambiguous requests and normalize aggressive collection behavior, including on sites where scraping may be sensitive or restricted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template encourages scraping arbitrary URLs and using external scraping/browser automation tools, but it provides no requirement to warn users that requested URLs and retrieved content may be transmitted to third-party infrastructure. This creates a real privacy and data-governance risk, especially if users provide internal, authenticated, sensitive, or legally restricted URLs for scraping.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template directs use of an external extract service on scraped URLs and content but does not disclose that page data may be transmitted to a third party. This creates a real privacy and data-governance risk because users may process proprietary, personal, or sensitive content without informed consent or policy review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guidance explicitly recommends using browser automation for content behind login walls but provides no safeguards around authenticated sessions, user consent, access authorization, or handling of sensitive/account-scoped data. In a web-scraping skill, this increases the chance an agent will collect private data from logged-in contexts or encourage terms-of-service or privacy violations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is for web research, but it includes guidance to use local file tools like Read, Grep, and Glob as workarounds for token limits. That expands the skill's operational scope into local repository exploration without a clear need tied to the stated purpose, which can encourage unnecessary access to local files and increase the chance of data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example explicitly promotes concurrent scraping of Etsy pages and browser automation, but it does not warn users about third-party data collection, rate limiting, terms-of-service, or site-impact concerns. In a web-scraping skill, omission of these safeguards can normalize indiscriminate collection behavior and increase the chance of abusive or non-compliant use, even though the content does not itself contain direct exploit code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The sample report and methodology present collected seller and listing data as normal output without disclosing that the workflow gathers and analyzes data from external websites. This omission reduces transparency and may lead users to overlook privacy, consent, provenance, and compliance considerations when using the skill for market research on third-party platforms.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.