Code Pluginsource linked

Apifyv0.5.1

Web scraping and AI-powered data extraction via Apify for OpenClaw — market research, competitor intelligence, trend analysis, lead generation, e-commerce, social media analytics, and more.

@apify/apify-openclaw-plugin·runtime apify·by @apify
Community code plugin. Review compatibility and verification before install.
openclaw plugins install clawhub:@apify/apify-openclaw-plugin
Latest release: v0.5.1Download zip

Compatibility

Built With Open Claw Version
2026.5.19
Plugin Api Range
>=1.0.0
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
high confidence
Purpose & Capability
The plugin’s stated purpose is to discover, start, and collect results from Apify Actors, including third-party scraping Actors; that behavior is disclosed and purpose-aligned, but it can transmit user-provided targets and inputs to Apify and Actor operators.
!
Instruction Scope
The runtime tool can start arbitrary Apify Actors without an allowlist or explicit per-run confirmation, and collected web content is marked as external but wrapped without a prominent warning in the returned text.
!
Install Mechanism
The setup helper always treats all tools as selected and writes tools.alsoAllow with group:plugins, which enables all plugin tools rather than only the Apify tool; the manual config path also prints the full API key to stdout.
Credentials
Network access to https://api.apify.com and use of an Apify API token are expected for this integration, and the code restricts the base URL to Apify, but scraping jobs may involve sensitive targets or personal data.
!
Persistence & Privilege
The setup flow mutates the OpenClaw config to persist the plugin, API key, and broad plugin-tool allowance; this is user-prompted, but the breadth of group:plugins is under-scoped for a single-tool plugin.
Scan Findings in Context
[SDI-4] unexpected: Accepted as a material concern: artifact code shows setup hardcodes allSelected=true and writes group:plugins, broadening tool authorization beyond the single Apify tool.
[SQP-2] expected: Partly accepted: sending actor IDs, queries, inputs, and collected data through Apify is expected for the product, but the documentation and runtime lack strong warnings about third-party Actors, privacy, and untrusted scraped output.
[SQP-2] unexpected: Accepted for the API-key handling instance: README claims API keys are never logged or included in output, while printManualConfig emits the full key to stdout.
What to consider before installing
Review this before installing. Use a limited Apify token if possible, avoid entering secrets or regulated data into Actor inputs, and change the generated tools.alsoAllow entry from group:plugins to the specific apify tool unless you intentionally want all plugin tools enabled. Treat scraped results as untrusted external content.
scripts/bump-openclaw.mjs:28
Shell command execution detected (child_process).
dist/cli.js:161
File appears to expose a hardcoded API secret or token.
src/cli.ts:189
File appears to expose a hardcoded API secret or token.
Patterns worth reviewing
These patterns may indicate risky behavior. Check the VirusTotal and OpenClaw results above for context-aware analysis before installing.

Verification

Tier
source linked
Scope
artifact only
Summary
Validated package structure and linked the release to source metadata.
Commit
0b6408ee77c6
Tag
main
Provenance
No
Scan status
suspicious

Tags

latest
0.5.1

Apify Plugin for OpenClaw

Universal web scraping and data extraction via Apify — 20k+ Actors across Instagram, Facebook, TikTok, YouTube, Google Maps, Google Search, e-commerce, and more.

Install

openclaw plugins install @apify/apify-openclaw-plugin

Restart the Gateway after installation.

How it works

The plugin registers a single tool — apify — with three actions:

ActionPurpose
discover + querySearch the Apify Store for Actors by keyword
discover + actorIdFetch an Actor's input schema + README
start + actorId + inputRun any Apify Actor, returns runId / datasetId
collect + runsPoll status and return results for completed runs

The tool uses a two-phase async pattern: start fires off a run and returns immediately. collect fetches results when the run completes. The agent does other work in between.

Get an API key

  1. Create an Apify account at https://console.apify.com/
  2. Generate an API token in Account Settings → Integrations.
  3. Store it in plugin config or set the APIFY_API_KEY environment variable.

Configure

{
  plugins: {
    entries: {
      "apify": {
        config: {
          apiKey: "apify_api_...",     // optional if APIFY_API_KEY env var is set
          baseUrl: "https://api.apify.com",
          maxResults: 20,
          enabledTools: [],           // empty = all tools enabled
        },
      },
    },
  },
  // Make the tool available to agents:
  tools: {
    alsoAllow: ["apify"],   // or "apify" or "group:plugins"
  },
}

Or use the interactive setup wizard:

openclaw apify setup

apify

Workflow

discover (search) → discover (schema) → start → collect
  1. Search — Find Actors: { action: "discover", query: "amazon price scraper" }
  2. Schema — Get input params: { action: "discover", actorId: "apify~google-search-scraper" }
  3. Start — Run the Actor: { action: "start", actorId: "apify~google-search-scraper", input: { queries: ["OpenAI"] } }
  4. Collect — Get results: { action: "collect", runs: [{ runId: "...", actorId: "...", datasetId: "..." }] }

Actor ID format

Actor IDs use the username~actor-name format (tilde separator, not slash).

Known Actors

The tool description includes 20k+ Actors across these categories:

  • Instagram — profiles, posts, comments, hashtags, reels, search, followers, tagged posts
  • Facebook — pages, posts, comments, likes, reviews, groups, events, ads, reels, photos, marketplace
  • TikTok — search, profiles, videos, comments, followers, hashtags, sounds, ads, trends, live
  • YouTube — search, channels, comments, shorts, video-by-hashtag
  • Google Maps — places, reviews, email extraction
  • Other — Google Search, Google Trends, Booking.com, TripAdvisor, contact info, e-commerce

Batching

Most Actors accept arrays of URLs/queries in their input (e.g., startUrls, queries). Always batch multiple targets into a single run — one run with 5 URLs is cheaper and faster than 5 separate runs.

Examples

// 1. Search the Apify Store
const search = await apify({
  action: "discover",
  query: "linkedin company scraper",
});

// 2. Get an Actor's input schema
const schema = await apify({
  action: "discover",
  actorId: "compass~crawler-google-places",
});

// 3. Start a Google Search scrape
const started = await apify({
  action: "start",
  actorId: "apify~google-search-scraper",
  input: { queries: ["OpenAI", "Anthropic"], maxPagesPerQuery: 1 },
  label: "search",
});
// -> { runs: [{ runId, actorId, datasetId, status }] }

// 4. Collect results
const results = await apify({
  action: "collect",
  runs: started.runs,
});
// -> { completed: [...], pending: [...] }

// Instagram profile scraping
await apify({
  action: "start",
  actorId: "apify~instagram-profile-scraper",
  input: { usernames: ["natgeo", "nasa"] },
});

// TikTok search
await apify({
  action: "start",
  actorId: "clockworks~tiktok-scraper",
  input: { searchQueries: ["AI tools"], resultsPerPage: 20 },
});

Sub-agent delegation

The tool description instructs agents to delegate apify calls to a sub-agent. The sub-agent handles the full discover → start → collect workflow and returns only the relevant extracted data — not raw API responses or run metadata.

Security

  • API keys are resolved from plugin config or APIFY_API_KEY env var — never logged or included in output.
  • Base URL validation — only https://api.apify.com prefix is allowed (SSRF prevention).
  • External content wrapping — all scraped results are wrapped with untrusted content markers.

Development

# Install dependencies
npm install

# Type check
npm run typecheck

# Run tests
npm test

# Build compiled output to dist/ (required for publish)
npm run build

# Pack (dry run) — npm runs `prepublishOnly` (build) automatically before packing
npm pack --dry-run

dist/ is generated by npm run build and is not checked in. The published npm tarball ships dist/ so newer OpenClaw versions (which no longer JIT-load TypeScript) can install the plugin.

Support

For issues with this integration, contact integrations@apify.com.

License

MIT