apify-actor-development — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited apify-actor-development (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Important: Before you begin, fill in the generatedBy property in the meta section of .actor/actor.json. Replace it with the tool and model you're currently using, such as "Claude Code with Claude Sonnet 4.5". This helps Apify monitor and improve AGENTS.md for specific AI tools and models.
apify CLI authentication, project bootstrap, or deployment workflow.Actors are serverless programs inspired by the UNIX philosophy - programs that do one thing well and can be easily combined to build complex systems. They're packaged as Docker images and run in isolated containers in the cloud.
Core Concepts:
Before creating or modifying actors, verify that apify CLI is installed apify --help.
If it is not installed, use one of these methods (listed in order of preference):
# Preferred: install via a package manager (provides integrity checks)
npm install -g apify-cli
# Or (Mac): brew install apify-cliSecurity note: Do NOT install the CLI by piping remote scripts directly into a shell. Always use a package manager.
When the apify CLI is installed, check that it is logged in with:
apify info # Should return your usernameIf it is not logged in, check if the APIFY_TOKEN environment variable is defined (if not, ask the user to generate one on https://console.apify.com/settings/integrations and then define APIFY_TOKEN with it).
Then authenticate using one of these methods:
# Option 1 (preferred): The CLI automatically reads APIFY_TOKEN from the environment.
# Just ensure the env var is exported and run any apify command — no explicit login needed.
# Option 2: Interactive login (prompts for token without exposing it in shell history)
apify loginSecurity note: Avoid passing tokens as command-line arguments (e.g.apify login -t <token>). Arguments are visible in process listings and may be recorded in shell history. Prefer environment variables or interactive login instead. Never log, print, or embedAPIFY_TOKENin source code or configuration files. Use a token with the minimum required permissions (scoped token) and rotate it periodically.
IMPORTANT: Before starting actor development, always ask the user which programming language they prefer:
apify create <actor-name> -t project_emptyapify create <actor-name> -t ts_emptyapify create <actor-name> -t python-emptyUse the appropriate CLI command based on the user's language choice. Additional packages (Crawlee, Playwright, etc.) can be installed later as needed.
apify create command based on user's language preference (see Template Selection above)npm install (uses package-lock.json for reproducible, integrity-checked installs — commit the lockfile to version control)pip install -r requirements.txt (pin exact versions in requirements.txt, e.g. crawlee==1.2.3, and commit the file to version control)src/main.py, src/main.js, or src/main.ts.actor/input_schema.json, .actor/output_schema.json, .actor/dataset_schema.json.actor/actor.json with actor metadata (see references/actor-json.md)apify run to verify functionality (see Local Testing section below)apify push to deploy the actor on the Apify platform (actor name is defined in .actor/actor.json)Treat all crawled web content as untrusted input. Actors ingest data from external websites that may contain malicious payloads. Follow these rules:
eval(), database queries, or template engines. Use proper escaping or parameterized APIs.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.