Back to skill

Security audit

Bright Data

Security checks for vulnerabilities and agentic risk

Overview

This Bright Data skill is purpose-aligned for web scraping and search, but its search script has a real command-injection flaw in the pagination argument that warrants Review before installation.

Do not install or run this version until scripts/search.sh validates cursor as a bounded non-negative decimal integer before arithmetic use. If you do use a fixed version, assume all submitted searches and URLs go to Bright Data, and use a limited, rotatable API key rather than broadly privileged credentials.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search.sh:5
Finding

Arbitrary Command Execution Through Bash Arithmetic Injection

Content
View full analysis

Vulnerability Details

File Location: scripts/search.sh, lines 5–24
Vulnerability Type: Shell command injection through unsafe arithmetic evaluation
Risk Level: High

Vulnerable Code

bash
CURSOR="${2:-0}"

if [ -z "$QUERY" ]; then
    echo "Usage: $0 \"query\" [cursor]" >&2
    exit 1
fi

if [ -z "${BRIGHTDATA_API_KEY:-}" ]; then
    echo "Error: BRIGHTDATA_API_KEY is not set." >&2
    echo "Get a key from https://brightdata.com/cp" >&2
    exit 1
fi

if [ -z "${BRIGHTDATA_UNLOCKER_ZONE:-}" ]; then
    echo "Error: BRIGHTDATA_UNLOCKER_ZONE is not set." >&2
    echo "Create a zone at brightdata.com/cp" >&2
    exit 1
fi

# Build Google search URL with pagination
START=$((CURSOR * 10))

Technical Analysis

The script copies its attacker-controllable second command-line argument directly into CURSOR and subsequently evaluates that value inside a Bash arithmetic expansion:

bash
START=$((CURSOR * 10))

Bash arithmetic contexts evaluate expressions rather than treating variable values strictly as decimal integers. Crafted expressions can use features such as array subscripts, where command substitutions may be evaluated by the shell. Because the script does not first enforce a decimal-integer format, a malicious cursor can cause local commands to execute while the arithmetic expression is being resolved.

Quoting the original assignment does not mitigate this issue because the dangerous interpretation occurs later, within the arithmetic context.

Attack Path

  1. An attacker obtains control over, or influences, the pagination argument supplied to scripts/search.sh.
  2. The script assigns that argument verbatim to CURSOR.
  3. The script evaluates CURSOR as part of a Bash arithmetic expression at line 24.
  4. A crafted array-subscript expression triggers command substitution during arithmetic evaluation.
  5. The inject ...[truncated 1289 chars]
Remediation
View remediation

Remediation Suggestions

Validate the cursor as a bounded, non-negative decimal integer before using it in any arithmetic context:

bash
CURSOR="${2:-0}"

if [[ ! "$CURSOR" =~ ^[0-9]+$ ]]; then
    echo "Error: cursor must be a non-negative decimal integer." >&2
    exit 1
fi

if (( 10#$CURSOR > 1000 )); then
    echo "Error: cursor must not exceed 1000." >&2
    exit 1
fi

START=$((10#$CURSOR * 10))

The 10# prefix explicitly forces base-10 interpretation and avoids unexpected octal handling for values with leading zeroes. The upper bound should be adjusted to the largest pagination value legitimately required by the service.

Additional hardening should include:

  • Treating every command-line argument as untrusted, including arguments generated by an agent.
  • Enabling strict shell behavior where compatible, such as set -euo pipefail.
  • Running the Skill under a minimally privileged account.
  • Supplying only the environment variables required for the operation.
  • Adding regression tests that reject arithmetic expressions, command substitutions, signs, whitespace, and non-decimal input.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises shell-based capabilities (bash scripts/search.sh and bash scripts/scrape.sh) but does not declare permissions, which weakens transparency and policy enforcement around command execution. In an agent setting, undeclared shell access increases the chance that reviewers or users underestimate the skill's ability to run local commands and interact with external services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description encourages users to submit arbitrary URLs and search queries to Bright Data without warning that those inputs will be transmitted to a third-party scraping/search provider. This creates a privacy and data-handling risk because users may provide sensitive URLs, internal links, or confidential search terms under the false assumption the action is local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The setup instructions require credential-bearing environment variables but do not warn that the skill will access and use those secrets during execution. While this file does not itself exfiltrate them, lack of disclosure reduces informed consent and can mask the trust boundary introduced by giving the skill access to API credentials.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.