finding-ecommerce-brands-for-outreach

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from social media platforms (Instagram and TikTok bios). This creates a surface for indirect prompt injection where malicious content in a bio could attempt to influence the agent during the filtering or ranking phases. * Ingestion points: Data returned from apidojo/instagram-scraper and apidojo/tiktok-scraper (Step 3). * Boundary markers: Absent in the ranking and formatting instructions. * Capability inventory: Subprocess calls via curl and node. * Sanitization: None specified for the bio excerpts displayed in the output table.
  • [DYNAMIC_EXECUTION]: The skill exposes the customMapFunction parameter, which accepts a JavaScript string for data transformation. While this is a standard feature of the underlying Apify actors, it allows for the execution of arbitrary JavaScript within the Apify environment.
  • [COMMAND_EXECUTION]: The skill provides instructions for executing shell commands via curl and node to interact with external APIs and local scripts. This requires the user to have an APIFY_TOKEN configured, which is handled via environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 06:36 PM
Security Audit — agent-trust-hub — finding-ecommerce-brands-for-outreach