pinterest-api
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill makes network requests to
api.scavio.dev. As these are the official API endpoints for the skill's author ('scavio-ai'), this represents intended functionality for a data-retrieval skill and is considered safe.\n- [CREDENTIALS_UNSAFE]: The skill correctly handles authentication by instructing the user to set aSCAVIO_API_KEYenvironment variable. It uses placeholder values likesk_live_your_keyandsk_your_key_herein documentation, which are recognized as safe practice for secret management education.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Pinterest (pin descriptions, bios, and board names). While this presents a theoretical injection surface, the skill includes explicit guardrails instructing the agent to summarize content, not build profiles of individuals, and to only return data exactly as provided by the API, which mitigates risk.
Audit Metadata