apify-ultimate-scraper

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill facilitates the execution of shell commands through the Apify CLI (apify). This includes searching for actors, fetching input schemas, and executing scraping tasks. It also suggests using the source command to load authentication tokens from a .env file.
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of the apify-cli via the Node Package Manager (npm) and involves executing "Actors," which are remote scraping scripts hosted and managed on the Apify platform.
  • [INDIRECT_PROMPT_INJECTION]: As a web scraping tool, the skill ingests data from external websites that are then processed and summarized by the agent. This creates a potential surface for indirect prompt injection if a scraped website contains malicious instructions intended to influence the agent's behavior.
  • Ingestion points: Data is retrieved from various web platforms using apify datasets get-items and presented to the agent for analysis or summarization.
  • Boundary markers: The skill does not explicitly define markers or delimiters to separate untrusted scraped content from agent instructions, though it recommends presenting data in a "formatted chat" style.
  • Capability inventory: The agent has the ability to execute CLI commands and write files to the local filesystem using a Write tool.
  • Sanitization: No specific sanitization or filtering protocols are provided for the ingested content before it is processed by the AI.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 09:21 AM
Security Audit — agent-trust-hub — apify-ultimate-scraper