apify-ultimate-scraper
Warn
Audited by Socket on Aug 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's behavior broadly matches its scraping purpose and uses Apify's official npm package and MCP endpoint, so it is not fundamentally incompatible with its stated role. The main risks are proportional but real: reading APIFY_TOKEN from .env, forwarding it to external tooling, reliance on an unverified local script, and broad delegation to many third-party Apify Actors that may handle user data outside Apify-owned code.
Confidence: 86%Severity: 57%
Audit Metadata