Skip to main content

tinybird

Enables the creation of real-time analytics APIs using Tinybird, allowing for fast data ingestion and SQL querying over HTTP.

Install this skill

or
69/100

Security score

The tinybird skill was audited on Mar 7, 2026 and we found 11 security issues across 4 threat categories. Review the findings below before installing.

Categories Tested

Security Issues

medium line 70

Template literal with variable interpolation in command context

SourceSKILL.md
70await fetch(`${TINYBIRD_URL}?name=events`, {
medium line 72

Template literal with variable interpolation in command context

SourceSKILL.md
72headers: { Authorization: `Bearer ${TINYBIRD_TOKEN}` },
medium line 136

Template literal with variable interpolation in command context

SourceSKILL.md
136{ headers: { Authorization: `Bearer ${TINYBIRD_TOKEN}` } }
medium line 144

Template literal with variable interpolation in command context

SourceSKILL.md
144`https://api.tinybird.co/v0/pipes/user_activity.json?user_id=${userId}&days=${days}`,
medium line 145

Template literal with variable interpolation in command context

SourceSKILL.md
145{ headers: { Authorization: `Bearer ${TINYBIRD_TOKEN}` } }
low line 134

Fetch to external URL

SourceSKILL.md
134const res = await fetch(
low line 63

Access to .env file

SourceSKILL.md
63const TINYBIRD_TOKEN = process.env.TINYBIRD_TOKEN;
low line 62

External URL reference

SourceSKILL.md
62const TINYBIRD_URL = "https://api.tinybird.co/v0/events";
low line 106

External URL reference

SourceSKILL.md
106-- GET https://api.tinybird.co/v0/pipes/daily_active_users.json
low line 135

External URL reference

SourceSKILL.md
135"https://api.tinybird.co/v0/pipes/daily_active_users.json",
low line 144

External URL reference

SourceSKILL.md
144`https://api.tinybird.co/v0/pipes/user_activity.json?user_id=${userId}&days=${days}`,
Scanned on Mar 7, 2026
View Security Dashboard