apify-actorization
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: A reference Dockerfile demonstrates tool installation by piping a remote script to a shell.
- Evidence:
RUN curl --silent --location https://raw.githubusercontent.com/houseabsolute/ubi/master/bootstrap/bootstrap-ubi.sh | shinreferences/cli-actorization.md. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates building web crawlers that ingest untrusted data from the internet, which can contain malicious instructions.
- Ingestion points: Data is ingested via
apify actor:get-inputinreferences/cli-actorization.mdandActor.getInput()in SDK-based implementations. - Boundary markers: The skill includes a 'Security' section advising to treat crawled content as untrusted and to avoid passing raw text to shell commands or
eval(). - Capability inventory: Generated Actors have access to shell command execution, network storage APIs, and potential file system access.
- Sanitization: The documentation explicitly instructs developers to sanitize crawled data and use parameterized APIs to prevent injection vulnerabilities.
Audit Metadata