instagram-api

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides standard documentation for API interaction using curl commands. These examples are informative and intended for user/agent reference to interact with the vendor's own API service.
  • [DATA_EXFILTRATION]: No evidence of unauthorized data harvesting or exfiltration. The skill facilitates access to public Instagram data via a proxy service. Network operations are restricted to the vendor's domain (instagram.fetcher.sh).
  • [CREDENTIALS_UNSAFE]: The documentation uses generic placeholders for API keys (e.g., bby_live_xxxxxxxxxxxx). It correctly instructs users to manage secrets via environment variables (FETCHER_API_KEY), which is a standard security practice.
  • [REMOTE_CODE_EXECUTION]: The skill does not contain patterns for downloading or executing remote code or scripts. The MCP configuration points to the vendor's official endpoint for tool definitions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 07:34 PM
Security Audit — agent-trust-hub — instagram-api