building-full-social-audit-for-brand

Warn

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill accepts a customMapFunction input parameter, described as a JavaScript function to transform output objects. This allows the execution of arbitrary JavaScript code provided as input.
  • [EXTERNAL_DOWNLOADS]: The skill is designed to interact with external services, specifically fetching data from Apify's API (api.apify.com) and executing actors from the apidojo namespace on the Apify platform.
  • [COMMAND_EXECUTION]: The instructions include bash commands using node to execute local scripts (scripts/run_actor.js) and curl for making REST API calls. While these are for the skill's primary purpose, they involve shell-level operations.
  • [CREDENTIALS_UNSAFE]: The skill relies on an APIFY_TOKEN environment variable. While it recommends using environment variables or a .env file (standard security practice), the workflow involves handling sensitive API credentials which could be exposed if the environment is compromised.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 2, 2026, 06:26 PM
Security Audit — agent-trust-hub — building-full-social-audit-for-brand