target-product-data

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts with 'api.scavio.dev', which matches the vendor's known infrastructure ('scavio-ai').
  • [SAFE]: Instructions for secret management follow best practices by advising the use of environment variables ('SCAVIO_API_KEY') and keeping keys out of source control.
  • [DATA_EXPOSURE_&_EXFILTRATION]: The skill performs network operations to 'api.scavio.dev'. As this is the vendor's primary API endpoint and no sensitive local files are accessed, this is considered normal functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from Target.com via the Scavio API. While this is an ingestion surface for untrusted data, the skill includes guardrails instructing the agent to never fabricate data and to verify URLs, reducing the risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 12:23 PM
Security Audit — agent-trust-hub — target-product-data