Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md Full OpenAPI spec: [openapi.json](openapi.json)
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real Apify scraping helper, but it includes broad Apify account and administration API access beyond the stated run-and-fetch workflow.
Review before installing. Use this skill only when you intentionally want an agent to use Apify with your APIFY_TOKEN, and avoid giving it sensitive internal URLs, private pages, credentials, personal data, or broad crawling tasks unless you have authorization. Prefer a token scoped to the minimum Apify permissions available, and confirm before any subscription, schedule, webhook, deletion, actor-editing, environment-variable, billing-limit, or large-crawl operation.
Referenced artifact was not completely inspected
Full OpenAPI spec: [openapi.json](openapi.json)
Referenced artifact was not completely inspected
Full OpenAPI spec: [openapi.json](openapi.json)
The OpenAPI specification exposes broad administrative capabilities far beyond the manifest’s stated purpose of running Actors and retrieving scraping results. It includes account management, billing/limits changes, storage CRUD, actor creation/deletion, source/version editing, and webhook/schedule administration, which materially expands what the skill could do if invoked or misused.
Actor source/version/environment-variable management enables creating, updating, and deleting code and secrets, not merely running an existing scraper. This gives the skill the ability to change executable logic and configure secrets, increasing the risk of code tampering, persistence, and sensitive configuration exposure.
User-account, billing, and limits endpoints allow access to private account data and modification of spending and retention settings, which are unrelated to a scraping runner skill. If exposed to an agent, they could leak sensitive account information or alter billing controls and retention behavior without clear user intent.
The skill description is broadly scoped around scraping, crawling, automation, and retrieving web data, which can cause the agent to invoke this skill for common web-related requests without clearly signaling that user-provided URLs and queries will be sent to a third-party service. This increases the chance of unintended external data disclosure and use of a powerful remote execution/scraping platform in contexts where a simpler local answer would suffice.
The documentation does not warn that URLs, queries, page targets, and actor inputs are transmitted to Apify, a third-party service. Users may provide sensitive internal URLs, authenticated targets, or confidential research terms without realizing they are being shared externally.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
You can also get the Actor's per-build OpenAPI spec (no auth required):
curl -s "https://api.apify.com/v2/acts/apify~web-scraper/builds/default/openapi.json"
Starting an actor sends user-supplied URLs and scraping parameters to Apify, enabling third-party processing of potentially sensitive browsing targets or instructions. Because the skill is specifically designed to run remote automation against arbitrary sites, the absence of explicit safety constraints makes unintended disclosure and misuse more likely.
Start the Actor and get the run object back immediately:
curl -s -X POST "https://api.apify.com/v2/acts/apify~web-scraper/runs" \
-H "Authorization: Bearer $APIFY_TOKEN" \
-H "Content-Type: application/json" \
-d '{"startUrls":[{"url":"https://example.com"}],"maxPagesPerCrawl":10}'
Retrieving dataset items from Apify pulls back scraped structured data that may include personal, proprietary, or otherwise sensitive information collected by the actor. The skill presents this as routine without cautioning that the data has already been transmitted to and processed by a third party, which is the substantive security concern in context.
Dataset items (most common — structured scraped data):
curl -s "https://api.apify.com/v2/datasets/DATASET_ID/items?clean=true&limit=100" \
-H "Authorization: Bearer $APIFY_TOKEN"
This shortcut endpoint retrieves dataset items for a run, again involving third-party handling of potentially sensitive scraped output. The danger is contextual rather than syntactic: the skill normalizes exfiltration of user-selected web content to Apify without explicit privacy and authorization guardrails.
Or directly from the run (shortcut — same parameters):
curl -s "https://api.apify.com/v2/actor-runs/RUN_ID/dataset/items?clean=true&limit=100" \
-H "Authorization: Bearer $APIFY_TOKEN"
This duplicate finding covers retrieval of screenshots, HTML, or OUTPUT records, which can expose raw page contents and sensitive artifacts through Apify. Such records are often more sensitive than normalized datasets because they may include tokens, account data, or full page state.
Key-value store record (screenshots, HTML, OUTPUT):
curl -s "https://api.apify.com/v2/key-value-stores/STORE_ID/records/OUTPUT" \
-H "Authorization: Bearer $APIFY_TOKEN"
This duplicate finding covers retrieval of screenshots, HTML, or OUTPUT records, which can expose raw page contents and sensitive artifacts through Apify. Such records are often more sensitive than normalized datasets because they may include tokens, account data, or full page state.
Key-value store record (screenshots, HTML, OUTPUT):
curl -s "https://api.apify.com/v2/key-value-stores/STORE_ID/records/OUTPUT" \
-H "Authorization: Bearer $APIFY_TOKEN"
Run logs may contain target URLs, actor inputs, error traces, and fragments of scraped data, so retrieving and relying on them can expose sensitive operational details through a third-party service. The skill does not caution about possible sensitive content in logs or advise minimizing their disclosure.
Run log:
curl -s "https://api.apify.com/v2/logs/RUN_ID" \
-H "Authorization: Bearer $APIFY_TOKEN"
Synchronous actor execution sends the full scraping job and immediately retrieves results from Apify, concentrating both outbound input sharing and inbound sensitive output handling in one step. This increases the chance that the skill is used casually for data collection without a pause for consent, authorization, or sensitivity review.
For Actors that finish within 300 seconds, get dataset items in one call:
curl -s -X POST "https://api.apify.com/v2/acts/apify~web-scraper/run-sync-get-dataset-items?timeout=120" \
-H "Authorization: Bearer $APIFY_TOKEN" \
-H "Content-Type: application/json" \
-d '{"startUrls":[{"url":"https://example.com"}],"maxPagesPerCrawl":5}'
The 'Scrape a website' recipe operationalizes third-party scraping with minimal friction and no warning about privacy, authorization, or the transmission of target URLs to Apify. Because this is a ready-to-run example, it materially increases the likelihood of unsafe use compared with more abstract API documentation.
curl -s -X POST "https://api.apify.com/v2/acts/apify~web-scraper/run-sync-get-dataset-items?timeout=120" \
-H "Authorization: Bearer $APIFY_TOKEN" \
-H "Content-Type: application/json" \
-d '{"startUrls":[{"url":"https://example.com"}],"maxPagesPerCrawl":20}'
The Google search scraping recipe can transmit potentially sensitive investigative queries to Apify and may be used for broad collection against third-party services. In context, the risk stems from normalized remote processing of user queries without disclosure or consent safeguards.
curl -s -X POST "https://api.apify.com/v2/acts/apify~google-search-scraper/run-sync-get-dataset-items?timeout=120" \
-H "Authorization: Bearer $APIFY_TOKEN" \
-H "Content-Type: application/json" \
-d '{"queries":"site:example.com openai","maxPagesPerQuery":1}'
The async workflow example starts a large crawl and sends substantial target scope and parameters to Apify, which can amplify external data transfer and unauthorized scraping if used incautiously. The example encourages scale ('maxPagesPerCrawl':500) without corresponding safeguards about permissions, sensitivity, or minimization.
# 1. Start
RUN=$(curl -s -X POST "https://api.apify.com/v2/acts/apify~web-scraper/runs?waitForFinish=60" \
-H "Authorization: Bearer $APIFY_TOKEN" \
-H "Content-Type: application/json" \
-d '{"startUrls":[{"url":"https://example.com"}],"maxPagesPerCrawl":500}')
Fetching final dataset items after a large crawl retrieves potentially voluminous scraped data that has been processed and stored by Apify. In the context of a large async crawl example, this reinforces the risk of collecting and exposing more third-party content than necessary without any minimization or sensitivity guidance.
done
curl -s "https://api.apify.com/v2/actor-runs/$RUN_ID/dataset/items?clean=true"
-H "Authorization: Bearer $APIFY_TOKEN"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "Apache 2.0",
"url": "https://www.apache.org/licenses/LICENSE-2.0.html"
},
"description": "\nThe Apify API (version 2) provides programmatic access to the [Apify\nplatform](https://docs.apify.com). The API is organized\naround [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer)\nHTTP endpoints.\n\nYou can download the complete OpenAPI schema of Apify API in the [YAML](http://docs.apify.com/api/openapi.yaml) or [JSON](http://docs.apify.com/api/openapi.json) formats. The source code is also available on [GitHub](https://github.com/apify/apify-docs/tree/master/apify-api/openapi).\n\nAll requests and responses (including errors) are encoded in\n[JSON](http://www.json.org/) format with UTF-8 encoding,\nwith a few exceptions that are explicitly described in the reference.\n\n- To access the API using [Node.js](https://nodejs.org/en/), we recommend the [`apify-client`](https://docs.apify.com/api/client/js) [NPM\npackage](https://www.npmjs.com/package/apify-client).\n- To access the API using [Python](https://www.python.org/), we recommend the [`apify-client`](https://docs.apify.com/api/client/python) [PyPI\npackage](https://pypi.org/project/apify-client/).\n\nThe clients' functions correspond to the API endpoints and have the same\nparameters. This simplifies development of apps that depend on the Apify\nplatform.\n\n:::note Important Request Details\n\n- `Content-Type` header: For requests with a JSON body, you must include the `Content-Type: application/json` header.\n\n- Method override: You can override the HTTP method using the `method` query parameter. This is useful for clients that can only send `GET` requests. For example, to call a `POST` endpoint, append `?method=POST` to the URL of your `GET` request.\n\n:::\n\n## Authentication\n<span id=\"/introduction/authentication\"></span>\n\nYou can find your API token on the\n[Integrations](https://console.apify.com/account#/integrations) page in the\nApify Console.\n\nTo use y
...[truncated 27 chars]
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "Apache 2.0",
"url": "https://www.apache.org/licenses/LICENSE-2.0.html"
},
"description": "\nThe Apify API (version 2) provides programmatic access to the [Apify\nplatform](https://docs.apify.com). The API is organized\naround [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer)\nHTTP endpoints.\n\nYou can download the complete OpenAPI schema of Apify API in the [YAML](http://docs.apify.com/api/openapi.yaml) or [JSON](http://docs.apify.com/api/openapi.json) formats. The source code is also available on [GitHub](https://github.com/apify/apify-docs/tree/master/apify-api/openapi).\n\nAll requests and responses (including errors) are encoded in\n[JSON](http://www.json.org/) format with UTF-8 encoding,\nwith a few exceptions that are explicitly described in the reference.\n\n- To access the API using [Node.js](https://nodejs.org/en/), we recommend the [`apify-client`](https://docs.apify.com/api/client/js) [NPM\npackage](https://www.npmjs.com/package/apify-client).\n- To access the API using [Python](https://www.python.org/), we recommend the [`apify-client`](https://docs.apify.com/api/client/python) [PyPI\npackage](https://pypi.org/project/apify-client/).\n\nThe clients' functions correspond to the API endpoints and have the same\nparameters. This simplifies development of apps that depend on the Apify\nplatform.\n\n:::note Important Request Details\n\n- `Content-Type` header: For requests with a JSON body, you must include the `Content-Type: application/json` header.\n\n- Method override: You can override the HTTP method using the `method` query parameter. This is useful for clients that can only send `GET` requests. For example, to call a `POST` endpoint, append `?method=POST` to the URL of your `GET` request.\n\n:::\n\n## Authentication\n<span id=\"/introduction/authentication\"></span>\n\nYou can find your API token on the\n[Integrations](https://console.apify.com/account#/integrations) page in the\nApify Console.\n\nTo use y
...[truncated 27 chars]
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "Apache 2.0",
"url": "https://www.apache.org/licenses/LICENSE-2.0.html"
},
"description": "\nThe Apify API (version 2) provides programmatic access to the [Apify\nplatform](https://docs.apify.com). The API is organized\naround [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer)\nHTTP endpoints.\n\nYou can download the complete OpenAPI schema of Apify API in the [YAML](http://docs.apify.com/api/openapi.yaml) or [JSON](http://docs.apify.com/api/openapi.json) formats. The source code is also available on [GitHub](https://github.com/apify/apify-docs/tree/master/apify-api/openapi).\n\nAll requests and responses (including errors) are encoded in\n[JSON](http://www.json.org/) format with UTF-8 encoding,\nwith a few exceptions that are explicitly described in the reference.\n\n- To access the API using [Node.js](https://nodejs.org/en/), we recommend the [`apify-client`](https://docs.apify.com/api/client/js) [NPM\npackage](https://www.npmjs.com/package/apify-client).\n- To access the API using [Python](https://www.python.org/), we recommend the [`apify-client`](https://docs.apify.com/api/client/python) [PyPI\npackage](https://pypi.org/project/apify-client/).\n\nThe clients' functions correspond to the API endpoints and have the same\nparameters. This simplifies development of apps that depend on the Apify\nplatform.\n\n:::note Important Request Details\n\n- `Content-Type` header: For requests with a JSON body, you must include the `Content-Type: application/json` header.\n\n- Method override: You can override the HTTP method using the `method` query parameter. This is useful for clients that can only send `GET` requests. For example, to call a `POST` endpoint, append `?method=POST` to the URL of your `GET` request.\n\n:::\n\n## Authentication\n<span id=\"/introduction/authentication\"></span>\n\nYou can find your API token on the\n[Integrations](https://console.apify.com/account#/integrations) page in the\nApify Console.\n\nTo use y
...[truncated 27 chars]
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "Apache 2.0",
"url": "https://www.apache.org/licenses/LICENSE-2.0.html"
},
"description": "\nThe Apify API (version 2) provides programmatic access to the [Apify\nplatform](https://docs.apify.com). The API is organized\naround [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer)\nHTTP endpoints.\n\nYou can download the complete OpenAPI schema of Apify API in the [YAML](http://docs.apify.com/api/openapi.yaml) or [JSON](http://docs.apify.com/api/openapi.json) formats. The source code is also available on [GitHub](https://github.com/apify/apify-docs/tree/master/apify-api/openapi).\n\nAll requests and responses (including errors) are encoded in\n[JSON](http://www.json.org/) format with UTF-8 encoding,\nwith a few exceptions that are explicitly described in the reference.\n\n- To access the API using [Node.js](https://nodejs.org/en/), we recommend the [`apify-client`](https://docs.apify.com/api/client/js) [NPM\npackage](https://www.npmjs.com/package/apify-client).\n- To access the API using [Python](https://www.python.org/), we recommend the [`apify-client`](https://docs.apify.com/api/client/python) [PyPI\npackage](https://pypi.org/project/apify-client/).\n\nThe clients' functions correspond to the API endpoints and have the same\nparameters. This simplifies development of apps that depend on the Apify\nplatform.\n\n:::note Important Request Details\n\n- `Content-Type` header: For requests with a JSON body, you must include the `Content-Type: application/json` header.\n\n- Method override: You can override the HTTP method using the `method` query parameter. This is useful for clients that can only send `GET` requests. For example, to call a `POST` endpoint, append `?method=POST` to the URL of your `GET` request.\n\n:::\n\n## Authentication\n<span id=\"/introduction/authentication\"></span>\n\nYou can find your API token on the\n[Integrations](https://console.apify.com/account#/integrations) page in the\nApify Console.\n\nTo use y
...[truncated 27 chars]
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "Apache 2.0",
"url": "https://www.apache.org/licenses/LICENSE-2.0.html"
},
"description": "\nThe Apify API (version 2) provides programmatic access to the [Apify\nplatform](https://docs.apify.com). The API is organized\naround [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer)\nHTTP endpoints.\n\nYou can download the complete OpenAPI schema of Apify API in the [YAML](http://docs.apify.com/api/openapi.yaml) or [JSON](http://docs.apify.com/api/openapi.json) formats. The source code is also available on [GitHub](https://github.com/apify/apify-docs/tree/master/apify-api/openapi).\n\nAll requests and responses (including errors) are encoded in\n[JSON](http://www.json.org/) format with UTF-8 encoding,\nwith a few exceptions that are explicitly described in the reference.\n\n- To access the API using [Node.js](https://nodejs.org/en/), we recommend the [`apify-client`](https://docs.apify.com/api/client/js) [NPM\npackage](https://www.npmjs.com/package/apify-client).\n- To access the API using [Python](https://www.python.org/), we recommend the [`apify-client`](https://docs.apify.com/api/client/python) [PyPI\npackage](https://pypi.org/project/apify-client/).\n\nThe clients' functions correspond to the API endpoints and have the same\nparameters. This simplifies development of apps that depend on the Apify\nplatform.\n\n:::note Important Request Details\n\n- `Content-Type` header: For requests with a JSON body, you must include the `Content-Type: application/json` header.\n\n- Method override: You can override the HTTP method using the `method` query parameter. This is useful for clients that can only send `GET` requests. For example, to call a `POST` endpoint, append `?method=POST` to the URL of your `GET` request.\n\n:::\n\n## Authentication\n<span id=\"/introduction/authentication\"></span>\n\nYou can find your API token on the\n[Integrations](https://console.apify.com/account#/integrations) page in the\nApify Console.\n\nTo use y
...[truncated 27 chars]
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "Apache 2.0",
"url": "https://www.apache.org/licenses/LICENSE-2.0.html"
},
"description": "\nThe Apify API (version 2) provides programmatic access to the [Apify\nplatform](https://docs.apify.com). The API is organized\naround [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer)\nHTTP endpoints.\n\nYou can download the complete OpenAPI schema of Apify API in the [YAML](http://docs.apify.com/api/openapi.yaml) or [JSON](http://docs.apify.com/api/openapi.json) formats. The source code is also available on [GitHub](https://github.com/apify/apify-docs/tree/master/apify-api/openapi).\n\nAll requests and responses (including errors) are encoded in\n[JSON](http://www.json.org/) format with UTF-8 encoding,\nwith a few exceptions that are explicitly described in the reference.\n\n- To access the API using [Node.js](https://nodejs.org/en/), we recommend the [`apify-client`](https://docs.apify.com/api/client/js) [NPM\npackage](https://www.npmjs.com/package/apify-client).\n- To access the API using [Python](https://www.python.org/), we recommend the [`apify-client`](https://docs.apify.com/api/client/python) [PyPI\npackage](https://pypi.org/project/apify-client/).\n\nThe clients' functions correspond to the API endpoints and have the same\nparameters. This simplifies development of apps that depend on the Apify\nplatform.\n\n:::note Important Request Details\n\n- `Content-Type` header: For requests with a JSON body, you must include the `Content-Type: application/json` header.\n\n- Method override: You can override the HTTP method using the `method` query parameter. This is useful for clients that can only send `GET` requests. For example, to call a `POST` endpoint, append `?method=POST` to the URL of your `GET` request.\n\n:::\n\n## Authentication\n<span id=\"/introduction/authentication\"></span>\n\nYou can find your API token on the\n[Integrations](https://console.apify.com/account#/integrations) page in the\nApify Console.\n\nTo use y
...[truncated 27 chars]
No suspicious patterns detected.