Atlas / Skills / jeremylongshore / Brightdata Core Workflow A

Brightdata Core Workflow ASAFE

skills/jeremylongshore/brightdata-core-workflow-a

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
2.0.0
Hosts
—
License
MIT
Stars
2,822
01

Overview

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Read from source at commit 4f83675ca38aOBSERVED · 2026-10-08
02

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: brightdata-core-workflow-a
description: 'Analyze an approved JavaScript-rendered task through Bright Data Browser API with bounded interaction and evidence. Use when a static request cannot satisfy an authorized public-data workflow and browser rendering is required. Trigger with: "use Bright Data Browser API", "connect Playwright to Bright Data", "collect a rendered public page".'
allowed-tools: Read, Grep, Write, Edit, Bash(python:*)
version: 2.0.0
argument-hint: "[browser-task-manifest]"
model: inherit
effort: high
license: MIT
author: Jeremy Longshore <[email protected]>
tags:
- saas
- web-data
- bright-data
- core-workflow-a
- operations
compatibility: 'Requires an approved Bright Data account or offline fixtures, current Bright Data documentation, and an authorized public-data collection purpose'
---
# Bright Data Browser API Run

## Overview

Treat Browser API as a remote-browser data plane, not an unlimited browsing identity. Bind one browser zone, a public-target manifest, an interaction ceiling, and a minimal output schema before connecting.

## Prerequisites

- A Browser API zone username/password stored in the runtime secret manager
- An approved public target and interaction manifest
- Playwright plus the reviewed Bright Data Python SDK or current documented client

## Instructions

### Step 1: Approve the task

Read the task manifest and Grep for login, account creation, purchase, message, or other prohibited interactions. Refuse any nonpublic or abusive workflow.

### Step 2: Connect through the SDK

Build the connect URL with the official client and keep credentials out of logs.

```python
from brightdata import BrightDataClient

client = BrightDataClient(
    browser_username=browser_user,
    browser_password=browser_password,
)
# Pass client.browser.get_connect_url() only to Playwright connect_over_cdp.
```

### Step 3: Constrain the page

Allow only the manifest host set, cap navigation and wall time, block unnecessary assets where appropriate, and extract only named public fields. Do not add evasion behavior after a policy denial.

### Step 4: Review and close

Use Bash(python:*) for fixture-backed browser tests. Persist the task ID, target class, field counts, provider errors, and policy decision; discard raw page content unless retention was explicitly approved.

## Tool Discipline

Use Read and Grep to verify the manifest and existing browser adapter. Use Write and Edit for the bounded task, schema, and tests. Use Bash(python:*) for offline tests; connecting a live browser still requires the recorded authorization gates.

## Output

- A bounded Browser API task manifest
- Schema-validated public fields and redacted run receipt
- Explicit close, retry, or policy-escalation result

## Examples

Use Browser API for an approved public page that requires JavaScript to render a price table. Navigate only to allowlisted hosts, extract the three approved fields, close the browser in `finally`, and reject any redirect to authentication.

## Error Handling

| Failure | Meaning | Response |
|---------|---------|----------|
| Connection is rejected | Zone credentials, entitlement, or egress is wrong | Verify the owned zone; do not expose the connect URL |
| Page redirects to login | The task crossed into nonpublic data | Stop and mark the target out of scope |
| Policy error is returned | Product or target is not authorized | Escalate; never add bypass behavior |

## Resources

- [Browser API](https://docs.brightdata.com/products/scraping-browser/introduction)
- [Python SDK](https://docs.brightdata.com/api-reference/SDK)
- [Acceptable use policy](https://docs.brightdata.com/general/policy/acceptable-use-policy)
- [Proxy error catalog](https://docs.brightdata.com/proxy-networks/errorCatalog)
03

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha 4f83675ca38afull audit observations/trust-audit/skill/jeremylongshore__brightdata-core-workflow-a.json · Report an issue / request a re-scan
04

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-084f83675ca38aSAFEB89first audit
05

Questions

What does the Brightdata Core Workflow A skill do?

Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.

Is Brightdata Core Workflow A safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Brightdata Core Workflow A access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

How current is this page?

The grade is for one exact copy of the source (4f83675ca38a), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement