Apify Results Query
Warn
Audited by Snyk on Mar 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.80). The skill queries and ingests results from Apify actor runs (apify_results / apify_mapped_records) via the apify-admin edge function — including examples like "last LinkedIn run" — which are scraped/untrusted third‑party web data that the agent reads, filters, and can act on (e.g., push to CRM), creating a clear vector for indirect prompt injection.
Audit Metadata