apify-competitor-intelligence

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from external platforms (e.g., social media comments, business reviews) via Apify Actors, which is then summarized by the agent.
  • Ingestion points: Untrusted data enters the agent context through the outputs of run_actor.js and fetch_actor_details.js which fetch content from various third-party websites.
  • Boundary markers: The instructions in SKILL.md (Step 5) do not provide explicit delimiters or instructions to the agent to isolate the scraped content or to ignore any potential instructions embedded within the retrieved data.
  • Capability inventory: The agent has the capability to execute Node.js scripts, write to the local filesystem, and perform network requests to the Apify API.
  • Sanitization: There is no evidence of content sanitization or validation performed on the scraped data to prevent the execution of malicious instructions hidden within comments or reviews.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 04:44 AM
Security Audit — agent-trust-hub — apify-competitor-intelligence