T09 · Insecure Skill Coding Practices
- Location
scripts/apify_twitter_actors.py:65- Finding
Apify API Token Transmitted in a URL Query Parameter
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to do what it says: run Apify-based Twitter/X follower collection with optional email enrichment, but users should handle privacy and API-token risks carefully.
Install only if you are authorized to collect and enrich this Twitter/X audience data. Prefer APIFY_TOKEN from a managed secret store instead of --apify-token, use a narrowly scoped/revocable Apify token, keep --include-emails off unless there is a lawful and policy-compliant reason, and pin dependencies/install sources for production use.
scripts/apify_twitter_actors.py:65Apify API Token Transmitted in a URL Query Parameter
scripts/apify_twitter_actors.py:257API Token Accepted and Documented as a Command-Line Argument
requirements.txt:1Unpinned Python and Installation Dependencies Reduce Supply-Chain Reproducibility
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
url = f"{APIFY_BASE}/{actor_id}/run-sync-get-dataset-items"
params = {"token": token, "format": "json", "clean": "true"}
resp = requests.post(url, params=params, json=payload, timeout=timeout_sec)
if resp.status_code >= 400:
raise SkillError(f"Actor {actor_id} failed: HTTP {resp.status_code} - {resp.text[:500]}")
The README promotes optional email enrichment and outreach-ready lead export but does not warn users that this workflow processes potentially sensitive personal data and may trigger privacy, consent, platform-policy, or regulatory obligations. In this skill context, the omission is more concerning because the stated purpose is lead generation and outbound automation, increasing the chance of misuse or non-compliant data handling at scale.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill documents use of environment variables and external network access to Apify actors, but it does not declare any explicit tool scope such as allowed tools or permissions. That creates an authorization and review gap: operators and automated policy systems cannot easily constrain or audit what the skill is permitted to access, increasing the chance of unintended network calls or secret exposure.
The skill explicitly supports collecting followers/following data and enriching usernames with email addresses, which is privacy-sensitive processing of personal data. Without any warning, consent guidance, or use restrictions, users may employ the workflow in ways that violate privacy expectations, platform rules, or internal compliance requirements.
The documentation tells users to pass the Apify API token as a command-line argument, which can leak secrets through shell history, process listings, CI logs, or telemetry. Since this token authorizes access to Apify resources, exposure could allow unauthorized actor execution, data access, or account abuse.
The skill explicitly supports collecting Twitter/X followers and then enriching those usernames into email addresses, but the contract provides no privacy, consent, rate-limit, or acceptable-use warning. That creates a real privacy and abuse risk because it operationalizes mass contact discovery for people derived from a target account's social graph, which can enable scraping, profiling, spam, or phishing at scale.
The troubleshooting example includes --include-emails in a minimal smoke test without any accompanying warning that email enrichment may collect or process sensitive personal data. In a skill explicitly designed for Twitter/X audience collection and enrichment, normalizing email collection as the default test path increases the chance that users will perform unnecessary PII enrichment, creating privacy, compliance, and data-handling risk.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
FOLLOWER_ACTOR_DEFAULT = "bIYXeMcKISYGnHhBG"
EMAIL_ACTOR_DEFAULT = "mSaHt2tt3Z7Fcwf0o"
APIFY_BASE = "https://api.apify.com/v2/acts"
class SkillError(Exception):
The script transmits user-supplied targets, collected usernames, and optionally enrichment inputs to an external service, which is an intentional capability of this skill. In context this is expected, but it is still security-relevant because it moves potentially sensitive collected data off-host to a third party, and the token is included in request parameters rather than a header.
url = f"{APIFY_BASE}/{actor_id}/run-sync-get-dataset-items"
params = {"token": token, "format": "json", "clean": "true"}
resp = requests.post(url, params=params, json=payload, timeout=timeout_sec)
if resp.status_code >= 400:
raise SkillError(f"Actor {actor_id} failed: HTTP {resp.status_code} - {resp.text[:500]}")
When --include-emails is used, the script forwards collected usernames to a second external Apify actor for enrichment without any explicit consent prompt or prominent disclosure at the point of use. In a data-collection skill, this matters because users may assume processing stays within the first actor/workflow, while the second transmission expands third-party sharing and privacy/compliance risk.
The dependency is specified as requests>=2.31.0, which allows installation of any newer release without guaranteeing reproducibility or review. This can introduce supply-chain risk and make builds silently pick up vulnerable or breaking versions over time, especially important in a skill that may interact with external APIs and process user-supplied URLs or handles.
requests>=2.31.0
The manifest includes requests without pinning an exact version, while the package has multiple known advisories across versions. Because the installed version is unconstrained beyond a minimum, it is not possible to verify from this file alone whether deployments will avoid affected releases, which is risky for a skill likely to make outbound HTTP requests and potentially handle attacker-controlled links or remote endpoints.
The code reads a sensitive API token from the APIFY_TOKEN environment variable to authenticate outbound requests. Under the code-file warning criteria, credential access should have some visible disclosure, comment, or documentation, and this file does not explain that environment credentials will be consumed.
No suspicious patterns detected.