keyapi-instagram-user-analysis

Pass

Audited by Gen Agent Trust Hub on Mar 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a transparent MCP client (scripts/run.js) that communicates exclusively with the vendor's authorized API endpoint (mcp.keyapi.ai). No unauthorized network activity or suspicious destinations were found.\n- [SAFE]: Sensitive credentials, specifically the KEYAPI_TOKEN, are managed securely through environment variables and a local .env file, avoiding the risk of hardcoded secrets.\n- [SAFE]: The provided scripts focus on legitimate data retrieval and caching operations. There is no evidence of obfuscation, dynamic code execution (eval/exec), or unauthorized system modifications.\n- [SAFE]: The skill metadata and documentation accurately reflect the code's functionality, and all external dependencies (e.g., @modelcontextprotocol/sdk) are standard industry packages.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 24, 2026, 12:10 PM
Security Audit — agent-trust-hub — keyapi-instagram-user-analysis