apify-integration-development

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents a workflow for processing untrusted web content and provides specific defense-in-depth instructions to mitigate potential injection.
  • Ingestion points: Actor dataset items derived from external web scraping (references/ai-harness-plugin.md).
  • Boundary markers: The instructions recommend wrapping content in delimiters such as <<<EXTERNAL_UNTRUSTED_CONTENT>>> (references/ai-harness-plugin.md).
  • Capability inventory: Integration tools perform network operations via apify-client and write to Key-Value storage (SKILL.md).
  • Sanitization: Guidance includes sanitizing forged markers within data and enforcing payload size limits (references/ai-harness-plugin.md).
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation and technical schemas from established service domains.
  • evidence: apify.com/openapi.json, apify.com/agents.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 01:41 AM
Security Audit — agent-trust-hub — apify-integration-development