apify-audience-analysis
Pass
Audited by Gen Agent Trust Hub on Mar 20, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes the
@apify/mcpcpackage from the official NPM registry. This is a legitimate utility provided by the vendor for platform interaction. - [COMMAND_EXECUTION]: The skill executes local Node.js scripts and the
mcpcCLI to automate data scraping. These commands are constrained to the skill's documented workflow and perform standard data processing tasks. - [DATA_EXFILTRATION]: User credentials, specifically the
APIFY_TOKEN, are transmitted exclusively to official Apify API endpoints (api.apify.comandmcp.apify.com) for authentication purposes. - [PROMPT_INJECTION]: The skill ingests untrusted content from social media platforms (e.g., comments, profile bios). While this represents a surface for indirect prompt injection, the skill does not possess high-risk capabilities (such as arbitrary code execution or filesystem write access) that would allow for exploitation.
Audit Metadata