datocms-feedback

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses platform-specific shell commands (open, xdg-open, start) to launch the user's browser with a generated URL. The instructions include safety measures such as single-quoting the URL to prevent shell interpretation of special characters.
  • [DATA_EXFILTRATION]: The skill drafts a feedback message based on conversation context to be sent to www.datocms.com. The process is guarded by strict sanitization rules that forbid the inclusion of credentials, tokens, or other private data. Since the destination is the vendor's own support domain, this is considered legitimate functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 07:36 PM
Security Audit — agent-trust-hub — datocms-feedback