Back to skill

Security audit

instagram-stories-scraper

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly performs a paid Apify-based Instagram Stories lookup and discloses the external service, billing, token use, and approval steps.

Install only if you are comfortable sending the requested Instagram usernames to Apify/DataVoyantLab and using a paid Apify account token. Review the displayed prices and exact maximum charge before approving each run, and avoid using it for private or sensitive account lists.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

Fetch the public Actor record before every run:

bash
curl -fsS "https://api.apify.com/v2/acts/dLL7b34nRrgN6ZV24"

From .data.pricingInfos, select the most recent entry whose startedAt is

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This call sends user-supplied Instagram usernames to an external third party and triggers a billable operation using the APIFY_TOKEN account. Although the skill discloses this behavior and requires user approval, it still represents a real data-exfiltration and external-action surface because user inputs are transmitted off-platform to a paid service.

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

For 10 or fewer usernames, use the synchronous dataset endpoint:

text
POST https://api.apify.com/v2/acts/dLL7b34nRrgN6ZV24/run-sync-get-dataset-items
  ?timeout=300
  &clean=true
  &format=json

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This asynchronous run request also transmits user-supplied usernames to Apify and initiates a billable external job under the user's APIFY_TOKEN. The risk is similar to the synchronous path, with added exposure from run IDs and dataset retrieval workflow if outputs or metadata are overexposed in logs or to unintended parties.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

For 11–100 usernames, start asynchronously:

text
POST https://api.apify.com/v2/acts/dLL7b34nRrgN6ZV24/runs
  ?waitForFinish=60
  &maxTotalChargeUsd=<calculated cap>

Static analysis

No suspicious patterns detected.