Back to skill

Security audit

Apify

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real Apify scraping helper, but it includes broad Apify account and administration API access beyond the stated run-and-fetch workflow.

Review before installing. Use this skill only when you intentionally want an agent to use Apify with your APIFY_TOKEN, and avoid giving it sensitive internal URLs, private pages, credentials, personal data, or broad crawling tasks unless you have authorization. Prefer a token scoped to the minimum Apify permissions available, and confirm before any subscription, schedule, webhook, deletion, actor-editing, environment-variable, billing-limit, or large-crawl operation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (55)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
Full OpenAPI spec: [openapi.json](openapi.json)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

md
Full OpenAPI spec: [openapi.json](openapi.json)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The OpenAPI specification exposes broad administrative capabilities far beyond the manifest’s stated purpose of running Actors and retrieving scraping results. It includes account management, billing/limits changes, storage CRUD, actor creation/deletion, source/version editing, and webhook/schedule administration, which materially expands what the skill could do if invoked or misused.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Actor source/version/environment-variable management enables creating, updating, and deleting code and secrets, not merely running an existing scraper. This gives the skill the ability to change executable logic and configure secrets, increasing the risk of code tampering, persistence, and sensitive configuration exposure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

User-account, billing, and limits endpoints allow access to private account data and modification of spending and retention settings, which are unrelated to a scraping runner skill. If exposed to an agent, they could leak sensitive account information or alter billing controls and retention behavior without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description is broadly scoped around scraping, crawling, automation, and retrieving web data, which can cause the agent to invoke this skill for common web-related requests without clearly signaling that user-provided URLs and queries will be sent to a third-party service. This increases the chance of unintended external data disclosure and use of a powerful remote execution/scraping platform in contexts where a simpler local answer would suffice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation does not warn that URLs, queries, page targets, and actor inputs are transmitted to Apify, a third-party service. Users may provide sensitive internal URLs, authenticated targets, or confidential research terms without realizing they are being shared externally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

You can also get the Actor's per-build OpenAPI spec (no auth required):

bash
curl -s "https://api.apify.com/v2/acts/apify~web-scraper/builds/default/openapi.json"

3. Run an Actor (async — recommended for most cases)

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

Starting an actor sends user-supplied URLs and scraping parameters to Apify, enabling third-party processing of potentially sensitive browsing targets or instructions. Because the skill is specifically designed to run remote automation against arbitrary sites, the absence of explicit safety constraints makes unintended disclosure and misuse more likely.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

Start the Actor and get the run object back immediately:

bash
curl -s -X POST "https://api.apify.com/v2/acts/apify~web-scraper/runs" \
  -H "Authorization: Bearer $APIFY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"startUrls":[{"url":"https://example.com"}],"maxPagesPerCrawl":10}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

Retrieving dataset items from Apify pulls back scraped structured data that may include personal, proprietary, or otherwise sensitive information collected by the actor. The skill presents this as routine without cautioning that the data has already been transmitted to and processed by a third party, which is the substantive security concern in context.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

Dataset items (most common — structured scraped data):

bash
curl -s "https://api.apify.com/v2/datasets/DATASET_ID/items?clean=true&limit=100" \
  -H "Authorization: Bearer $APIFY_TOKEN"

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This shortcut endpoint retrieves dataset items for a run, again involving third-party handling of potentially sensitive scraped output. The danger is contextual rather than syntactic: the skill normalizes exfiltration of user-selected web content to Apify without explicit privacy and authorization guardrails.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

Or directly from the run (shortcut — same parameters):

bash
curl -s "https://api.apify.com/v2/actor-runs/RUN_ID/dataset/items?clean=true&limit=100" \
  -H "Authorization: Bearer $APIFY_TOKEN"

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This duplicate finding covers retrieval of screenshots, HTML, or OUTPUT records, which can expose raw page contents and sensitive artifacts through Apify. Such records are often more sensitive than normalized datasets because they may include tokens, account data, or full page state.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

Key-value store record (screenshots, HTML, OUTPUT):

bash
curl -s "https://api.apify.com/v2/key-value-stores/STORE_ID/records/OUTPUT" \
  -H "Authorization: Bearer $APIFY_TOKEN"

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This duplicate finding covers retrieval of screenshots, HTML, or OUTPUT records, which can expose raw page contents and sensitive artifacts through Apify. Such records are often more sensitive than normalized datasets because they may include tokens, account data, or full page state.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

Key-value store record (screenshots, HTML, OUTPUT):

bash
curl -s "https://api.apify.com/v2/key-value-stores/STORE_ID/records/OUTPUT" \
  -H "Authorization: Bearer $APIFY_TOKEN"

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

Run logs may contain target URLs, actor inputs, error traces, and fragments of scraped data, so retrieving and relying on them can expose sensitive operational details through a third-party service. The skill does not caution about possible sensitive content in logs or advise minimizing their disclosure.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

Run log:

bash
curl -s "https://api.apify.com/v2/logs/RUN_ID" \
  -H "Authorization: Bearer $APIFY_TOKEN"

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

Synchronous actor execution sends the full scraping job and immediately retrieves results from Apify, concentrating both outbound input sharing and inbound sensitive output handling in one step. This increases the chance that the skill is used casually for data collection without a pause for consent, authorization, or sensitivity review.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

For Actors that finish within 300 seconds, get dataset items in one call:

bash
curl -s -X POST "https://api.apify.com/v2/acts/apify~web-scraper/run-sync-get-dataset-items?timeout=120" \
  -H "Authorization: Bearer $APIFY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"startUrls":[{"url":"https://example.com"}],"maxPagesPerCrawl":5}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The 'Scrape a website' recipe operationalizes third-party scraping with minimal friction and no warning about privacy, authorization, or the transmission of target URLs to Apify. Because this is a ready-to-run example, it materially increases the likelihood of unsafe use compared with more abstract API documentation.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

Scrape a website

bash
curl -s -X POST "https://api.apify.com/v2/acts/apify~web-scraper/run-sync-get-dataset-items?timeout=120" \
  -H "Authorization: Bearer $APIFY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"startUrls":[{"url":"https://example.com"}],"maxPagesPerCrawl":20}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The Google search scraping recipe can transmit potentially sensitive investigative queries to Apify and may be used for broad collection against third-party services. In context, the risk stems from normalized remote processing of user queries without disclosure or consent safeguards.

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

Google search

bash
curl -s -X POST "https://api.apify.com/v2/acts/apify~google-search-scraper/run-sync-get-dataset-items?timeout=120" \
  -H "Authorization: Bearer $APIFY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"queries":"site:example.com openai","maxPagesPerQuery":1}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The async workflow example starts a large crawl and sends substantial target scope and parameters to Apify, which can amplify external data transfer and unauthorized scraping if used incautiously. The example encourages scale ('maxPagesPerCrawl':500) without corresponding safeguards about permissions, sensitivity, or minimization.

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

bash
# 1. Start
RUN=$(curl -s -X POST "https://api.apify.com/v2/acts/apify~web-scraper/runs?waitForFinish=60" \
  -H "Authorization: Bearer $APIFY_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"startUrls":[{"url":"https://example.com"}],"maxPagesPerCrawl":500}')

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

Fetching final dataset items after a large crawl retrieves potentially voluminous scraped data that has been processed and stored by Apify. In the context of a large async crawl example, this reinforces the risk of collecting and exposing more third-party content than necessary without any minimization or sensitivity guidance.

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

done

3. Fetch results

curl -s "https://api.apify.com/v2/actor-runs/$RUN_ID/dataset/items?clean=true"
-H "Authorization: Bearer $APIFY_TOKEN"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
"name": "Apache 2.0",
      "url": "https://www.apache.org/licenses/LICENSE-2.0.html"
    },
    "description": "\nThe Apify API (version 2) provides programmatic access to the [Apify\nplatform](https://docs.apify.com). The API is organized\naround [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer)\nHTTP endpoints.\n\nYou can download the complete OpenAPI schema of Apify API in the [YAML](http://docs.apify.com/api/openapi.yaml) or [JSON](http://docs.apify.com/api/openapi.json) formats. The source code is also available on [GitHub](https://github.com/apify/apify-docs/tree/master/apify-api/openapi).\n\nAll requests and responses (including errors) are encoded in\n[JSON](http://www.json.org/) format with UTF-8 encoding,\nwith a few exceptions that are explicitly described in the reference.\n\n- To access the API using [Node.js](https://nodejs.org/en/), we recommend the [`apify-client`](https://docs.apify.com/api/client/js) [NPM\npackage](https://www.npmjs.com/package/apify-client).\n- To access the API using [Python](https://www.python.org/), we recommend the [`apify-client`](https://docs.apify.com/api/client/python) [PyPI\npackage](https://pypi.org/project/apify-client/).\n\nThe clients' functions correspond to the API endpoints and have the same\nparameters. This simplifies development of apps that depend on the Apify\nplatform.\n\n:::note Important Request Details\n\n- `Content-Type` header: For requests with a JSON body, you must include the `Content-Type: application/json` header.\n\n- Method override: You can override the HTTP method using the `method` query parameter. This is useful for clients that can only send `GET` requests. For example, to call a `POST` endpoint, append `?method=POST` to the URL of your `GET` request.\n\n:::\n\n## Authentication\n<span id=\"/introduction/authentication\"></span>\n\nYou can find your API token on the\n[Integrations](https://console.apify.com/account#/integrations) page in the\nApify Console.\n\nTo use y
...[truncated 27 chars]

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
"name": "Apache 2.0",
      "url": "https://www.apache.org/licenses/LICENSE-2.0.html"
    },
    "description": "\nThe Apify API (version 2) provides programmatic access to the [Apify\nplatform](https://docs.apify.com). The API is organized\naround [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer)\nHTTP endpoints.\n\nYou can download the complete OpenAPI schema of Apify API in the [YAML](http://docs.apify.com/api/openapi.yaml) or [JSON](http://docs.apify.com/api/openapi.json) formats. The source code is also available on [GitHub](https://github.com/apify/apify-docs/tree/master/apify-api/openapi).\n\nAll requests and responses (including errors) are encoded in\n[JSON](http://www.json.org/) format with UTF-8 encoding,\nwith a few exceptions that are explicitly described in the reference.\n\n- To access the API using [Node.js](https://nodejs.org/en/), we recommend the [`apify-client`](https://docs.apify.com/api/client/js) [NPM\npackage](https://www.npmjs.com/package/apify-client).\n- To access the API using [Python](https://www.python.org/), we recommend the [`apify-client`](https://docs.apify.com/api/client/python) [PyPI\npackage](https://pypi.org/project/apify-client/).\n\nThe clients' functions correspond to the API endpoints and have the same\nparameters. This simplifies development of apps that depend on the Apify\nplatform.\n\n:::note Important Request Details\n\n- `Content-Type` header: For requests with a JSON body, you must include the `Content-Type: application/json` header.\n\n- Method override: You can override the HTTP method using the `method` query parameter. This is useful for clients that can only send `GET` requests. For example, to call a `POST` endpoint, append `?method=POST` to the URL of your `GET` request.\n\n:::\n\n## Authentication\n<span id=\"/introduction/authentication\"></span>\n\nYou can find your API token on the\n[Integrations](https://console.apify.com/account#/integrations) page in the\nApify Console.\n\nTo use y
...[truncated 27 chars]

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
"name": "Apache 2.0",
      "url": "https://www.apache.org/licenses/LICENSE-2.0.html"
    },
    "description": "\nThe Apify API (version 2) provides programmatic access to the [Apify\nplatform](https://docs.apify.com). The API is organized\naround [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer)\nHTTP endpoints.\n\nYou can download the complete OpenAPI schema of Apify API in the [YAML](http://docs.apify.com/api/openapi.yaml) or [JSON](http://docs.apify.com/api/openapi.json) formats. The source code is also available on [GitHub](https://github.com/apify/apify-docs/tree/master/apify-api/openapi).\n\nAll requests and responses (including errors) are encoded in\n[JSON](http://www.json.org/) format with UTF-8 encoding,\nwith a few exceptions that are explicitly described in the reference.\n\n- To access the API using [Node.js](https://nodejs.org/en/), we recommend the [`apify-client`](https://docs.apify.com/api/client/js) [NPM\npackage](https://www.npmjs.com/package/apify-client).\n- To access the API using [Python](https://www.python.org/), we recommend the [`apify-client`](https://docs.apify.com/api/client/python) [PyPI\npackage](https://pypi.org/project/apify-client/).\n\nThe clients' functions correspond to the API endpoints and have the same\nparameters. This simplifies development of apps that depend on the Apify\nplatform.\n\n:::note Important Request Details\n\n- `Content-Type` header: For requests with a JSON body, you must include the `Content-Type: application/json` header.\n\n- Method override: You can override the HTTP method using the `method` query parameter. This is useful for clients that can only send `GET` requests. For example, to call a `POST` endpoint, append `?method=POST` to the URL of your `GET` request.\n\n:::\n\n## Authentication\n<span id=\"/introduction/authentication\"></span>\n\nYou can find your API token on the\n[Integrations](https://console.apify.com/account#/integrations) page in the\nApify Console.\n\nTo use y
...[truncated 27 chars]

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
"name": "Apache 2.0",
      "url": "https://www.apache.org/licenses/LICENSE-2.0.html"
    },
    "description": "\nThe Apify API (version 2) provides programmatic access to the [Apify\nplatform](https://docs.apify.com). The API is organized\naround [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer)\nHTTP endpoints.\n\nYou can download the complete OpenAPI schema of Apify API in the [YAML](http://docs.apify.com/api/openapi.yaml) or [JSON](http://docs.apify.com/api/openapi.json) formats. The source code is also available on [GitHub](https://github.com/apify/apify-docs/tree/master/apify-api/openapi).\n\nAll requests and responses (including errors) are encoded in\n[JSON](http://www.json.org/) format with UTF-8 encoding,\nwith a few exceptions that are explicitly described in the reference.\n\n- To access the API using [Node.js](https://nodejs.org/en/), we recommend the [`apify-client`](https://docs.apify.com/api/client/js) [NPM\npackage](https://www.npmjs.com/package/apify-client).\n- To access the API using [Python](https://www.python.org/), we recommend the [`apify-client`](https://docs.apify.com/api/client/python) [PyPI\npackage](https://pypi.org/project/apify-client/).\n\nThe clients' functions correspond to the API endpoints and have the same\nparameters. This simplifies development of apps that depend on the Apify\nplatform.\n\n:::note Important Request Details\n\n- `Content-Type` header: For requests with a JSON body, you must include the `Content-Type: application/json` header.\n\n- Method override: You can override the HTTP method using the `method` query parameter. This is useful for clients that can only send `GET` requests. For example, to call a `POST` endpoint, append `?method=POST` to the URL of your `GET` request.\n\n:::\n\n## Authentication\n<span id=\"/introduction/authentication\"></span>\n\nYou can find your API token on the\n[Integrations](https://console.apify.com/account#/integrations) page in the\nApify Console.\n\nTo use y
...[truncated 27 chars]

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
"name": "Apache 2.0",
      "url": "https://www.apache.org/licenses/LICENSE-2.0.html"
    },
    "description": "\nThe Apify API (version 2) provides programmatic access to the [Apify\nplatform](https://docs.apify.com). The API is organized\naround [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer)\nHTTP endpoints.\n\nYou can download the complete OpenAPI schema of Apify API in the [YAML](http://docs.apify.com/api/openapi.yaml) or [JSON](http://docs.apify.com/api/openapi.json) formats. The source code is also available on [GitHub](https://github.com/apify/apify-docs/tree/master/apify-api/openapi).\n\nAll requests and responses (including errors) are encoded in\n[JSON](http://www.json.org/) format with UTF-8 encoding,\nwith a few exceptions that are explicitly described in the reference.\n\n- To access the API using [Node.js](https://nodejs.org/en/), we recommend the [`apify-client`](https://docs.apify.com/api/client/js) [NPM\npackage](https://www.npmjs.com/package/apify-client).\n- To access the API using [Python](https://www.python.org/), we recommend the [`apify-client`](https://docs.apify.com/api/client/python) [PyPI\npackage](https://pypi.org/project/apify-client/).\n\nThe clients' functions correspond to the API endpoints and have the same\nparameters. This simplifies development of apps that depend on the Apify\nplatform.\n\n:::note Important Request Details\n\n- `Content-Type` header: For requests with a JSON body, you must include the `Content-Type: application/json` header.\n\n- Method override: You can override the HTTP method using the `method` query parameter. This is useful for clients that can only send `GET` requests. For example, to call a `POST` endpoint, append `?method=POST` to the URL of your `GET` request.\n\n:::\n\n## Authentication\n<span id=\"/introduction/authentication\"></span>\n\nYou can find your API token on the\n[Integrations](https://console.apify.com/account#/integrations) page in the\nApify Console.\n\nTo use y
...[truncated 27 chars]

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 181)May include surrounding context.

md
"name": "Apache 2.0",
      "url": "https://www.apache.org/licenses/LICENSE-2.0.html"
    },
    "description": "\nThe Apify API (version 2) provides programmatic access to the [Apify\nplatform](https://docs.apify.com). The API is organized\naround [RESTful](https://en.wikipedia.org/wiki/Representational_state_transfer)\nHTTP endpoints.\n\nYou can download the complete OpenAPI schema of Apify API in the [YAML](http://docs.apify.com/api/openapi.yaml) or [JSON](http://docs.apify.com/api/openapi.json) formats. The source code is also available on [GitHub](https://github.com/apify/apify-docs/tree/master/apify-api/openapi).\n\nAll requests and responses (including errors) are encoded in\n[JSON](http://www.json.org/) format with UTF-8 encoding,\nwith a few exceptions that are explicitly described in the reference.\n\n- To access the API using [Node.js](https://nodejs.org/en/), we recommend the [`apify-client`](https://docs.apify.com/api/client/js) [NPM\npackage](https://www.npmjs.com/package/apify-client).\n- To access the API using [Python](https://www.python.org/), we recommend the [`apify-client`](https://docs.apify.com/api/client/python) [PyPI\npackage](https://pypi.org/project/apify-client/).\n\nThe clients' functions correspond to the API endpoints and have the same\nparameters. This simplifies development of apps that depend on the Apify\nplatform.\n\n:::note Important Request Details\n\n- `Content-Type` header: For requests with a JSON body, you must include the `Content-Type: application/json` header.\n\n- Method override: You can override the HTTP method using the `method` query parameter. This is useful for clients that can only send `GET` requests. For example, to call a `POST` endpoint, append `?method=POST` to the URL of your `GET` request.\n\n:::\n\n## Authentication\n<span id=\"/introduction/authentication\"></span>\n\nYou can find your API token on the\n[Integrations](https://console.apify.com/account#/integrations) page in the\nApify Console.\n\nTo use y
...[truncated 27 chars]

Static analysis

No suspicious patterns detected.