bright-data-best-practices

Warn

Audited by Snyk on Mar 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill documentation (SKILL.md and references/web-scraper-api.md) explicitly instructs the agent to fetch and ingest content from arbitrary public websites using Web Unlocker, SERP API, Web Scraper API and Browser API—including social sites like Reddit/Twitter/Instagram—and even recommends converting scraped pages to markdown for LLM pipelines, which exposes the agent to untrusted third‑party content that can influence subsequent actions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 4, 2026, 06:26 AM