apify-actorization

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: A reference Dockerfile demonstrates tool installation by piping a remote script to a shell.
  • Evidence: RUN curl --silent --location https://raw.githubusercontent.com/houseabsolute/ubi/master/bootstrap/bootstrap-ubi.sh | sh in references/cli-actorization.md.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates building web crawlers that ingest untrusted data from the internet, which can contain malicious instructions.
  • Ingestion points: Data is ingested via apify actor:get-input in references/cli-actorization.md and Actor.getInput() in SDK-based implementations.
  • Boundary markers: The skill includes a 'Security' section advising to treat crawled content as untrusted and to avoid passing raw text to shell commands or eval().
  • Capability inventory: Generated Actors have access to shell command execution, network storage APIs, and potential file system access.
  • Sanitization: The documentation explicitly instructs developers to sanitize crawled data and use parameterized APIs to prevent injection vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 03:13 PM
Security Audit — agent-trust-hub — apify-actorization