pier-cloud
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a legitimate API integration toolset. It provides structured scripts for interacting with the Pier Cloud FinOps platform.
- [CREDENTIALS_UNSAFE]: The skill correctly implements credential management by instructing the user to store sensitive API keys (
PIERCLOUD_CLIENT_ID,PIERCLOUD_CLIENT_SECRET) in a.envfile. No hardcoded secrets were found in the source code or documentation. - [EXTERNAL_DOWNLOADS]: All external dependencies are standard, reputable Python packages (
requests,python-dotenv). No suspicious third-party downloads or remote script executions were identified. - [DATA_EXFILTRATION]: Network activity is restricted to the official API domain (
api.piercloud.io). The scripts do not exhibit any patterns of sending sensitive data to unauthorized external endpoints. - [COMMAND_EXECUTION]: The scripts are designed as command-line tools using the
argparselibrary to handle user input safely. There are no instances of arbitrary command execution or shell injection vulnerabilities.
Audit Metadata