Apify Run Trigger

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aligns with its stated purpose and contains no direct signs of obfuscation or overt malware in the provided YAML. Primary risks are architectural and operational: centralized apify-admin intermediary, lack of documented credential scoping, no actor whitelist or URL validation, and limited cost/rate controls. These increase the chance of data exposure, credential forwarding, abuse to target sensitive endpoints, or unexpected costs. Recommended actions before deployment: ensure apify-admin is a trusted, audited component; apply least-privilege Apify credentials; implement actor whitelists and URL validation; log and audit run requests; and enforce cost/rate limits and clear user warnings in previews.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 3, 2026, 11:38 AM
Package URL
pkg:socket/skills-sh/SixtySecondsApp%2Fuse60%2Fapify-run-trigger%2F@6e17f3f351b73dd442d33f087df3cd999515fbf1