apify-generate-output-schema

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and analyzes source code files (JavaScript, TypeScript, Python) and configuration files (actor.json) from the project directory. This creates a potential surface where maliciously crafted comments or content within the analyzed code could influence the agent's behavior. However, the risk is minimal as the skill's capabilities are restricted to generating and updating static JSON configuration files on the local filesystem.
  • Ingestion points: Reads actor.json and project source code files throughout the repository.
  • Boundary markers: None explicitly defined to separate analyzed content from instructions.
  • Capability inventory: Reads local files; writes and updates dataset_schema.json, output_schema.json, key_value_store_schema.json, and actor.json.
  • Sanitization: No explicit sanitization or validation of the ingested external content is mentioned before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 10:26 AM
Security Audit — agent-trust-hub — apify-generate-output-schema