apify-plan-travel

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill exhibits safe design patterns by requiring the agent to verify data sources, schemas, and price basis before providing travel recommendations. It uses standard vendor resources from the Apify platform via authorized tool interfaces (MCP) without performing direct shell executions or downloading untrusted scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external web scrapers (Google Flights and Hotels). While this constitutes an attack surface for indirect prompt injection, the risk is mitigated by the skill's focus on structured data analysis and the absence of high-risk capabilities (such as arbitrary command execution or file system modification) that could be triggered by malicious data. The instructions explicitly mandate the inspection of payloads and schemas, which serves as a validation step.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:20 PM
Security Audit — agent-trust-hub — apify-plan-travel