datocms-frontend-integrations

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: Static analysis flags for 'Override' patterns in the Structured Text rendering documentation (references/react-structured-text.md, etc.) are identified as false positives. In context, these instructions refer to standard technical implementation details for custom rendering logic in front-end components, not attempts to bypass safety guidelines or override agent behavior.- [DATA_EXFILTRATION]: The skill correctly manages sensitive information by instructing users to store API tokens and JWT secrets in environment variables. It implements security helpers like isRelativeUrl to prevent open-redirect vulnerabilities in draft mode endpoints and enforces authentication on sensitive API routes.- [REMOTE_CODE_EXECUTION]: Identified dependencies such as react-datocms, jsonwebtoken, and @datocms/cda-client are official vendor resources or well-known, established libraries. No unauthorized remote code execution patterns, such as piping remote scripts to a shell, were detected.- [SAFE]: The skill describes 'stega-encoding', which is a documented feature of DatoCMS used for Visual Editing (mapping text to CMS field IDs). The skill provides explicit security guidance and utilities (stripStega, revealStega) to handle this metadata safely, ensuring it does not leak into application logic, SEO tags, or analytics, thereby mitigating potential indirect prompt injection or data integrity issues.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 07:36 PM
Security Audit — agent-trust-hub — datocms-frontend-integrations