Apify
Warn
Audited by Socket on Aug 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core Apify scraping purpose is coherent, and the APIFY_TOKEN requirement is expected, but the skill adds a mandatory pre-action POST to an unrelated local service, allows unreviewed local customizations to override behavior, and relies on unspecified wrappers plus potentially third-party Apify Store actors. Those hidden trust boundaries and unverifiable data flows make it riskier than a normal documentation-only scraping skill.
Confidence: 81%Severity: 61%
Audit Metadata