apify-booking-host-leads

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the Apify CLI (apify actors call) to invoke multiple remote data extraction tools. This includes executing commands with specific inputs and user-agent strings.
  • [EXTERNAL_DOWNLOADS]: The workflow relies on several community-maintained and official tools hosted on the Apify platform, such as voyager/booking-scraper, lukaskrivka/google-maps-with-contact-details, and vdrmota/contact-info-scraper. These are external scripts executed as part of the data enrichment pipeline.
  • [DATA_EXFILTRATION]: The skill is designed to systematically scrape and aggregate contact information (emails, phone numbers, and addresses) from Booking.com and other public web sources. While this is the stated purpose, it involves significant automated data harvesting from external platforms.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its use of AI-based web scraping. It ingests content from arbitrary external websites and processes it using apify/ai-web-scraper with a natural language prompt.
  • Ingestion points: Data is pulled from external accommodation websites discovered via search results.
  • Boundary markers: No boundary markers or instructions to ignore embedded commands are present in the extraction prompts.
  • Capability inventory: The agent has the capability to execute remote actors and write results to persistent datasets.
  • Sanitization: There is no evidence of sanitization or filtering of the external website content before it is processed by the LLM-based scraper.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 04:14 PM
Security Audit — agent-trust-hub — apify-booking-host-leads