apify-public-registries

Warn

Audited by Snyk on Jun 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.78). Outsider free text is ingested when the DE/UK/RO workflows call Apify scraping actors (e.g., reference/scripts/DE/fetch_all.pymcpc ... call-actor for radeance/handelsregister-api, reference/scripts/UK/fetch_all.pydhrumil/company-house-scraper, reference/scripts/RO/fetch_all.pyapify/website-content-crawler), and the actor’s scraped page text is returned as structuredContent/items that the script then serializes and (in the agent’s runtime) can be placed into LLM context.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill invokes Apify actors at runtime (e.g., via "apify call apify/website-content-crawler" and mcpc calls to actors like "radeance/handelsregister-api", "dhrumil/company-house-scraper", and "minute_contest/poland-krs-financial-scraper"), which executes remote scraping code on Apify and is a required runtime dependency for DE/UK/PL/CZ/RO lookups — this meets the criteria for executing remote code during skill runtime.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 13, 2026, 12:39 PM
Issues
2
Security Audit — snyk — apify-public-registries