bright-data-best-practices

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill is documentation for legitimate Bright Data integrations and does not contain executable malware or hidden exfiltration code. The primary security concerns are operational: (1) it requires sensitive credentials (API keys and browser auth) that, if mishandled or leaked, allow remote use of the account and access to fetched data; (2) it embeds browser credentials in connection URLs (wss://... and https://...@host) which increases risk of credential exposure in logs/processes; and (3) all scraped content and requests transit Bright Data infrastructure by design, so users must trust the provider and consider privacy and compliance implications. Overall the material is coherent with its stated purpose but warrants cautious handling of credentials and storage of retrieved content.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 06:28 AM
Package URL
pkg:socket/skills-sh/brightdata%2Fskills%2Fbright-data-best-practices%2F@8fe9665ebc18d61a32515fbe287603b299a9bae1