AGENT LAB: SKILLS

apify-trend-analysis

Warn

Audited by Snyk on Feb 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill launches Apify actors that scrape public social sites (e.g., Instagram, Facebook, TikTok, YouTube, Google Trends listed in SKILL.md) and then downloads and displays dataset items from the Apify API endpoint (https://api.apify.com/v2/datasets/{datasetId}/items) in displayQuickAnswer/downloadResults, meaning the agent ingests and presents untrusted, user-generated third‑party content as part of its workflow.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill issues runtime requests to the Apify API (e.g., POST to https://api.apify.com/v2/acts/{author~actor}/runs?token=...) to start Apify actors and later fetch dataset items, which causes execution of remote code on Apify and is a required runtime dependency.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 10:24 PM