Apify Run Trigger
Audited by Socket on Mar 3, 2026
1 alert found:
Obfuscated FileThe skill aligns with its stated purpose and contains no direct signs of obfuscation or overt malware in the provided YAML. Primary risks are architectural and operational: centralized apify-admin intermediary, lack of documented credential scoping, no actor whitelist or URL validation, and limited cost/rate controls. These increase the chance of data exposure, credential forwarding, abuse to target sensitive endpoints, or unexpected costs. Recommended actions before deployment: ensure apify-admin is a trusted, audited component; apply least-privilege Apify credentials; implement actor whitelists and URL validation; log and audit run requests; and enforce cost/rate limits and clear user warnings in previews.