klaviyo-prod-checklist
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a comprehensive checklist for production deployment of Klaviyo integrations, promoting security best practices like secret management and webhook signature verification.
- [COMMAND_EXECUTION]: Uses
grepto scan the local codebase for potential hardcoded API keys (pk_) andcurlto interact with Klaviyo APIs. These tools are used for their intended purpose of auditing and validation. - [EXTERNAL_DOWNLOADS]: Interacts with official Klaviyo domains (
status.klaviyo.comanda.klaviyo.com) to check service status and validate API keys. These are official service endpoints for the Klaviyo integration and are documented neutrally. - [SAFE]: The skill includes instructions to identify potential credential leaks in the user's code and encourages the use of secret managers for API keys, which aligns with standard industry security practices.
Audit Metadata