apify-integration-development
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents a workflow for processing untrusted web content and provides specific defense-in-depth instructions to mitigate potential injection.
- Ingestion points: Actor dataset items derived from external web scraping (references/ai-harness-plugin.md).
- Boundary markers: The instructions recommend wrapping content in delimiters such as <<<EXTERNAL_UNTRUSTED_CONTENT>>> (references/ai-harness-plugin.md).
- Capability inventory: Integration tools perform network operations via apify-client and write to Key-Value storage (SKILL.md).
- Sanitization: Guidance includes sanitizing forged markers within data and enforcing payload size limits (references/ai-harness-plugin.md).
- [EXTERNAL_DOWNLOADS]: The skill fetches documentation and technical schemas from established service domains.
- evidence: apify.com/openapi.json, apify.com/agents.md.
Audit Metadata