pier-cloud

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a legitimate API integration toolset. It provides structured scripts for interacting with the Pier Cloud FinOps platform.
  • [CREDENTIALS_UNSAFE]: The skill correctly implements credential management by instructing the user to store sensitive API keys (PIERCLOUD_CLIENT_ID, PIERCLOUD_CLIENT_SECRET) in a .env file. No hardcoded secrets were found in the source code or documentation.
  • [EXTERNAL_DOWNLOADS]: All external dependencies are standard, reputable Python packages (requests, python-dotenv). No suspicious third-party downloads or remote script executions were identified.
  • [DATA_EXFILTRATION]: Network activity is restricted to the official API domain (api.piercloud.io). The scripts do not exhibit any patterns of sending sensitive data to unauthorized external endpoints.
  • [COMMAND_EXECUTION]: The scripts are designed as command-line tools using the argparse library to handle user input safely. There are no instances of arbitrary command execution or shell injection vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 07:55 PM
Security Audit — agent-trust-hub — pier-cloud