klaviyo-core-workflow-a
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate integration patterns for the Klaviyo SaaS platform using official developer documentation and SDK patterns.
- [CREDENTIALS_SAFE]: The skill follows security best practices by instructing the user to store the sensitive 'KLAVIYO_PRIVATE_KEY' in environment variables rather than hardcoding it.
- [COMMAND_EXECUTION]: The skill uses standard Node.js/TypeScript code snippets for API interactions; no dangerous shell command executions or remote script downloads were detected.
- [DATA_EXPOSURE]: Data handling is limited to the synchronization of customer profiles to a designated third-party marketing service (Klaviyo) as per the stated intent of the skill.
Audit Metadata