Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Apply Bright Data security best practices for secrets and access control. Use when securing API keys, implementing least privilege access, or auditing Bright Data security configuration. Trigger with phrases like "brightdata security", "brightdata secrets", "secure brightdata", "brightdata API key security".
.claude/skills/jeremylongshore-brightdata-security-basics/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 2% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 22% | 0% |
| case-04 | ✗→✓ | ▲ Improved | 51% | 0% |
| case-12 | ✗→✓ | ▲ Improved | 39% | 0% |
| case-13 | ✗→✓ | ▲ Improved | 26% | 0% |
Treat legal purpose, public-data scope, account roles, zone isolation, and application controls as one authorization chain. Provider access does not replace the customer's duty to restrict targets, fields, retention, and downstream use.
Read the use case and Grep manifests for authenticated pages, personal or sensitive fields, messaging, purchases, account creation, or other prohibited activity. Refuse nonpublic information behind login.
Choose named-user API keys or product-specific zone credentials, apply the least account role, isolate environments, and document revocation. Never encode secret values in configuration examples.
Write target and field allowlists, maximum records and bytes, retention, rate and cost ceilings, redirect rules, and fail-closed policy handling. Provider denial cannot trigger automatic evasion.
Edit tests to cover disallowed hosts, login redirects, secret redaction, oversized results, policy errors, and revoked access. Record owner approval and the next review condition.
Use Read and Grep to inspect policy, roles, configuration, and tests. Use Write and Edit only for approved manifests, controls, tests, and the security receipt. This skill grants no live collection or account-administration authority.
Authorize a public product-price dataset with named fields and short retention. Deny login redirects and free-form URLs, bind one production zone to one worker role, and make every policy 403 a hard stop.
| Failure | Meaning | Response | |---------|---------|----------| | Target ownership or purpose is missing | Authorization chain is incomplete | Stop before provisioning credentials | | Account-wide key is shared broadly | Blast radius is excessive | Issue named-user access or a narrower zone credential | | Collected fields exceed the manifest | Application guardrail failed | Quarantine output and open an incident |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-10 | pass→pass | 11,390 | 5,081 | -55% | 1 | 1 | 0% | 1,989 | 1,865 | -6% | 0 | 0 | — |
case-01 | fail→pass | 18,390 | 11,605 | -37% | 1 | 1 | 0% | 3,499 | 3,564 | +2% | 0 | 0 | — |
case-02 | fail→fail | 14,852 | 10,511 | -29% | 1 | 1 | 0% | 2,688 | 3,086 | +15% | 0 | 0 | — |
case-03 | fail→pass | 16,441 | 12,929 | -21% | 1 | 1 | 0% | 2,880 | 3,505 | +22% | 0 | 0 | — |
case-04 | fail→pass | 10,125 | 9,245 | -9% | 1 | 1 | 0% | 1,915 | 2,891 | +51% | 0 | 0 | — |
case-05 | pass→pass | 15,185 | 16,070 | +6% | 1 | 1 | 0% | 2,533 | 3,901 | +54% | 0 | 0 | — |
case-06 | pass→pass | 10,050 | 8,067 | -20% | 1 | 1 | 0% | 1,597 | 2,432 | +52% | 0 | 0 | — |
case-07 | pass→pass | 24,017 | 2,978 | -88% | 1 | 1 | 0% | 1,820 | 1,609 | -12% | 0 | 0 | — |
case-08 | pass→pass | 11,005 | 9,851 | -10% | 1 | 1 | 0% | 2,091 | 3,028 | +45% | 0 | 0 | — |
case-09 | pass→pass | 11,980 | 5,367 | -55% | 1 | 1 | 0% | 2,084 | 1,970 | -5% | 0 | 0 | — |
case-11 | pass→pass | 10,201 | 5,674 | -44% | 1 | 1 | 0% | 1,997 | 2,300 | +15% | 0 | 0 | — |
case-12 | fail→pass | 6,546 | 3,109 | -53% | 1 | 1 | 0% | 1,175 | 1,630 | +39% | 0 | 0 | — |
case-13 | fail→pass | 9,552 | 5,400 | -43% | 1 | 1 | 0% | 1,572 | 1,973 | +26% | 0 | 0 | — |
case-14 | pass→pass | 15,809 | 10,804 | -32% | 1 | 1 | 0% | 3,035 | 3,177 | +5% | 0 | 0 | — |
case-15 | pass→pass | 13,895 | 9,097 | -35% | 1 | 1 | 0% | 2,333 | 2,716 | +16% | 0 | 0 | — |
case-16 | pass→pass | 13,106 | 5,780 | -56% | 1 | 1 | 0% | 1,948 | 2,039 | +5% | 0 | 0 | — |
case-17 | pass→pass | 15,053 | 7,985 | -47% | 1 | 1 | 0% | 1,990 | 2,504 | +26% | 0 | 0 | — |
case-18 | fail→pass | 10,355 | 2,659 | -74% | 1 | 1 | 0% | 1,554 | 1,396 | -10% | 0 | 0 | — |
case-19 | fail→pass | 11,519 | 5,638 | -51% | 1 | 1 | 0% | 1,934 | 1,984 | +3% | 0 | 0 | — |
case-20 | pass→pass | 7,733 | 4,146 | -46% | 1 | 1 | 0% | 1,508 | 1,822 | +21% | 0 | 0 | — |
case-21 | pass→pass | 13,029 | 6,788 | -48% | 1 | 1 | 0% | 1,986 | 1,973 | -1% | 0 | 0 | — |
case-22 | pass→pass | 6,091 | 1,875 | -69% | 1 | 1 | 0% | 890 | 1,339 | +50% | 0 | 0 | — |
case-23 | pass→pass | 7,056 | 3,413 | -52% | 1 | 1 | 0% | 1,268 | 1,503 | +19% | 0 | 0 | — |
case-24 | pass→pass | 11,413 | 13,143 | +15% | 1 | 1 | 0% | 1,847 | 2,447 | +32% | 0 | 0 | — |
case-25 | pass→pass | 11,653 | 5,471 | -53% | 1 | 1 | 0% | 1,826 | 2,010 | +10% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 25 cases were attempted. The headline lift of +28 percentage points is the difference between those two pass rates over the 25 comparable cases.
The publisher has shipped newer versions since this run, so these numbers describe v1, not the version currently listed.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.