apify-booking-host-leads

Warn

Audited by Snyk on Jun 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). Tier 2/3/4 runtime paths fetch outsider-authored web content (Google Maps results, Google Search snippets/URLs, and scraped third-party websites) and pass the extracted free text (emails/phones/website/contact text) into the agent/LLM context for processing.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill calls third‑party Apify actors at runtime (e.g., apify/ai-web-scraper and other actor IDs invoked via the Apify API / MCP endpoint https://mcp.apify.com), which execute remote code and in the case of apify/ai-web-scraper accept a prompt string from the skill — and the workflow depends on these actors for required functionality.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 18, 2026, 08:10 PM
Issues
2
Security Audit — snyk — apify-booking-host-leads