keyapi-pinterest-analysis

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's functionality broadly matches its stated Pinterest-analysis purpose, and its install path is relatively ordinary, but all requests and auth are routed through KeyAPI's own MCP endpoint instead of an official Pinterest API. That intermediary data flow and token dependency create medium security risk and trust concentration, though there is no clear evidence of malware or hidden payload execution.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:11 PM
Package URL
pkg:socket/skills-sh/EchoSell%2Fkeyapi-skills%2Fkeyapi-pinterest-analysis%2F@c021252a5ee9ce2880d7140990545c768f3f85e9