apify-ultimate-scraper
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands through the Apify CLI (
apify). This includes searching for actors, fetching input schemas, and executing scraping tasks. It also suggests using thesourcecommand to load authentication tokens from a.envfile. - [EXTERNAL_DOWNLOADS]: The skill requires the installation of the
apify-clivia the Node Package Manager (npm) and involves executing "Actors," which are remote scraping scripts hosted and managed on the Apify platform. - [INDIRECT_PROMPT_INJECTION]: As a web scraping tool, the skill ingests data from external websites that are then processed and summarized by the agent. This creates a potential surface for indirect prompt injection if a scraped website contains malicious instructions intended to influence the agent's behavior.
- Ingestion points: Data is retrieved from various web platforms using
apify datasets get-itemsand presented to the agent for analysis or summarization. - Boundary markers: The skill does not explicitly define markers or delimiters to separate untrusted scraped content from agent instructions, though it recommends presenting data in a "formatted chat" style.
- Capability inventory: The agent has the ability to execute CLI commands and write files to the local filesystem using a
Writetool. - Sanitization: No specific sanitization or filtering protocols are provided for the ingested content before it is processed by the AI.
Audit Metadata