The skill executes unpinned remote code and performs unauthorized network and file operations without declaring necessary security constraints or tool permissions, posing a significant risk of arbitrary code execution.
npx skills add https://github.com/apify/agent-skillsRemote code download and execution detected
curl … | bash
Global/unverified dependency execution — global npm/yarn package, dotnet tool, or auto-confirmed npx run without version or integrity pinning
npm install -g
Unpinned npx package execution — `npx <pkg>` without a version pin pulls latest from npm at runtime
npx apify
SKILL.md links to "references/actor-json.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/actor-json.md](references/actor-json.md)
SKILL.md links to "references/actor-readme.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/actor-readme.md](references/actor-readme.md)
SKILL.md links to "references/input-schema.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/input-schema.md](references/input-schema.md)
SKILL.md links to "references/logging.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/logging.md](references/logging.md)
SKILL.md links to "references/standby-mode.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/standby-mode.md](references/standby-mode.md)
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/apify/agent-skills/apify-actor-development)<a href="https://mondoo.com/ai-agent-security/skills/github/apify/agent-skills/apify-actor-development"><img src="https://mondoo.com/ai-agent-security/api/badge/github/apify/agent-skills/apify-actor-development.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/apify/agent-skills/apify-actor-development.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.