skills/danielmiessler/lifeos/Apify/Gen Agent Trust Hub

Apify

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions in SKILL.md include a curl command to a local notification endpoint (http://localhost:31337/notify). This is used for signaling the start of workflows within the LifeOS environment and is considered a benign use of shell commands.\n- [EXTERNAL_DOWNLOADS]: The skill uses the apify-client Node.js package (version 2.22.3) to communicate with the Apify platform. All external communications are directed towards official Apify API endpoints, which is a well-known and trusted service.\n- [REMOTE_CODE_EXECUTION]: The web-scraper actor wrapper (actors/web/web-scraper.ts) supports a pageFunction parameter. This allows the agent to provide custom JavaScript code that is executed on the remote Apify infrastructure to perform specific scraping logic. This is a legitimate feature of the integrated service.\n- [DATA_EXFILTRATION]: The skill is designed to extract public data from various social and business platforms (Instagram, LinkedIn, Google Maps, etc.). It includes capabilities to extract business contact information like emails and phone numbers, which is the primary purpose of the lead generation actors.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:47 AM
Security Audit — agent-trust-hub — Apify