apify-trend-analysis

Pass

Audited by Gen Agent Trust Hub on Apr 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides shell commands for fetching Actor schemas via mcpc and running analysis scripts using Node.js.\n- [EXTERNAL_DOWNLOADS]: The run_actor.js script and SKILL.md fetch configuration and data from Apify's official domains (api.apify.com and mcp.apify.com), which are well-known technology services.\n- [PROMPT_INJECTION]: The skill ingests untrusted data from social media platforms, creating a surface for indirect prompt injection.\n
  • Ingestion points: External trend data from Instagram, TikTok, Facebook, YouTube, and Google Trends (processed in SKILL.md via Actor results).\n
  • Boundary markers: Absent; the instructions do not include delimiters or warnings for the agent to ignore instructions embedded in the external content.\n
  • Capability inventory: The skill has file-write capabilities via fs.writeFileSync in run_actor.js.\n
  • Sanitization: No sanitization or escaping is performed on the scraped data before it is presented to the agent for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 17, 2026, 02:51 AM