scraping-twitter-profiles

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl and node shell commands to interface with the Apify API and run local automation scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted profile metadata from Twitter which could contain malicious content. 1. Ingestion points: Twitter handles and profile data (bios, names) retrieved via the Apify API. 2. Capability inventory: Shell commands (curl, node) and tool execution (apify:run-actor). 3. Boundary markers: Absent; data is displayed in markdown tables without isolation. 4. Sanitization: Limited to basic handle normalization (removing prefix symbols).
  • [DYNAMIC_EXECUTION]: The customMapFunction input parameter allows providing JavaScript code as a string to be executed in the remote scraping environment for data transformation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 08:55 PM
Security Audit — agent-trust-hub — scraping-twitter-profiles