T09 · Insecure Skill Coding Practices
- Location
SKILL.md:46- Finding
Apify API Token Exposed in URL Query Strings
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but it relies on a user Apify token and repeatedly places that token in request URLs, which is a credential-handling risk users should review before installing.
Review this before installing if your Apify token has broad permissions or billing access. Use a narrow, revocable token where possible, avoid copying examples that put tokens in URLs, prefer Authorization headers, and assume TikTok URLs, scraping settings, and collected comment data will be processed by Apify.
SKILL.md:46Apify API Token Exposed in URL Query Strings
Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.
|-----------|------|----------|-------------|
| `videoUrls` | array of strings | **Yes** | TikTok post URLs (video, photo, or short links). Max 50, must be unique. |
| `maxCommentsPerVideo` | integer | No | Max top-level comments per post. Default: 100. Min: 1, Max: 5000 |
| `includeReplies` | boolean | No | Collect threaded replies. Default: true |
| `maxRepliesPerComment` | integer | No | Max replies per comment. Default: 50. Min: 1, Max: 500 |
## Complete Example (Python)
The trigger phrases are somewhat broad because they include generic requests like analyzing TikTok engagement, which could cause the skill to activate in contexts broader than strict comment scraping. This is not directly exploitable like code execution, but it can lead to unintended invocation and surprise data transfer to the external Apify service.
The skill sends user-supplied TikTok URLs and retrieves comment data through a third-party service, but the description does not warn users that their inputs and resulting data are transmitted to Apify. This creates a transparency and privacy risk because users may not realize external processing occurs.
The presence of the Apify API base URL indicates the skill is designed to communicate with an external service. By itself this line is only an endpoint definition, but in context it supports real outbound data flow and therefore contributes to the external transmission concern.
import requests, os, time
TOKEN = os.environ["APIFY_API_TOKEN"]
BASE = "https://api.apify.com/v2"
# Step 1: Start the run
response = requests.post(
This code explicitly transmits user-provided TikTok URLs and scraping parameters to the Apify API, which is a third-party external service. The transmission itself is expected for the skill's function, but it is still a real data egress point with privacy and data-handling implications.
BASE = "https://api.apify.com/v2"
# Step 1: Start the run
response = requests.post(
f"{BASE}/acts/futurizerush~tiktok-comment-scraper/runs?token={TOKEN}",
json={
"videoUrls": [
This example also sends user-specified TikTok URLs to Apify, including potentially multiple videos in one request, increasing the volume of externally shared data. In context this is intended functionality, but it remains a genuine external transmission risk.
requests.post(
f"{BASE}/acts/futurizerush~tiktok-comment-scraper/runs?token={TOKEN}",
json={
"videoUrls": [
The bash example transmits data to Apify and includes the API token directly in the request URL, which can increase exposure through shell history, logs, proxies, or process inspection. Although common in simple examples, this is a security weakness in addition to the underlying third-party transmission.
# Step 1: Start the run
RUN_RESPONSE=$(curl -s -X POST \
"https://api.apify.com/v2/acts/futurizerush~tiktok-comment-scraper/runs?token=$APIFY_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{"videoUrls": ["https://www.tiktok.com/@bellapoarch/video/6862153058223197445"], "maxCommentsPerVideo": 20, "includeReplies": true}')
This endpoint usage shows a POST request to Apify with the API token in the URL, combining external transmission with unnecessary credential exposure risk. If logs or monitoring capture request URLs, the token may be disclosed.
# Step 1: Start the run
RUN_RESPONSE=$(curl -s -X POST \
"https://api.apify.com/v2/acts/futurizerush~tiktok-comment-scraper/runs?token=$APIFY_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{"videoUrls": ["https://www.tiktok.com/@bellapoarch/video/6862153058223197445"], "maxCommentsPerVideo": 20, "includeReplies": true}')
Polling the external Apify run-status endpoint is another outbound call to the third-party service. It does not add much new data exposure beyond the initial submission, but it confirms ongoing interaction with the external processor.
# Step 2: Poll until done
while true; do
STATUS=$(curl -s "https://api.apify.com/v2/actor-runs/$RUN_ID?token=$APIFY_API_TOKEN" \
| jq -r '.data.status')
[ "$STATUS" = "SUCCEEDED" ] && break
[ "$STATUS" = "FAILED" ] || [ "$STATUS" = "ABORTED" ] && echo "Failed: $STATUS" && exit 1
Fetching dataset items from Apify returns scraped TikTok comments and replies from a third-party system, which means retrieved content flows through and is exposed to that external platform. This is integral to the skill, but it still creates privacy, compliance, and data residency concerns.
done
curl -s "https://api.apify.com/v2/datasets/$DATASET_ID/items?token=$APIFY_API_TOKEN" | jq '.'
## Output Format
No suspicious patterns detected.