!
Third-party audit

Gen Agent Trust Hub

apify-lead-generation · apify/agent-skills

Review
Provider summary

The skill facilitates lead generation via web scraping but introduces several security risks. It constructs shell commands dynamically from user-provided input, which could allow for command injection. It also reads sensitive credentials from a local .env file and passes them through shell pipes, and it depends on an external NPM package from a non-pre-approved source. Furthermore, it lacks sanitization for data scraped from social media platforms, creating a surface for indirect prompt injection.

The provider classified the analyzed snapshot as MEDIUM risk. This result applies to the content available at audit time.

Provider
Gen Agent Trust Hub
Normalized result
warn
Risk level
MEDIUM
Audited
Feb 17, 2026
Interpretation

How to use this signal

01

Confirm the source

Compare the repository, publisher, and installation command before continuing.

02

Read the content

Review SKILL.md, scripts, and allowed tools. Artificial Atlas never executes them during indexing.

03

Limit permissions

Use the narrowest possible scope and avoid broad credentials for third-party skills.