skills/scavio-ai/skills/pinterest-api/Gen Agent Trust Hub

pinterest-api

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill makes network requests to api.scavio.dev. As these are the official API endpoints for the skill's author ('scavio-ai'), this represents intended functionality for a data-retrieval skill and is considered safe.\n- [CREDENTIALS_UNSAFE]: The skill correctly handles authentication by instructing the user to set a SCAVIO_API_KEY environment variable. It uses placeholder values like sk_live_your_key and sk_your_key_here in documentation, which are recognized as safe practice for secret management education.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from Pinterest (pin descriptions, bios, and board names). While this presents a theoretical injection surface, the skill includes explicit guardrails instructing the agent to summarize content, not build profiles of individuals, and to only return data exactly as provided by the API, which mitigates risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 12:23 PM
Security Audit — agent-trust-hub — pinterest-api