skills/openhands/extensions/datadog/Gen Agent Trust Hub

datadog

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses curl (Linux) and curl.exe (Windows) to make authenticated requests to the Datadog API. These commands are necessary for the skill's primary function of monitoring and debugging.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data from official Datadog API endpoints (e.g., api.datadoghq.com). These network operations are directed at a well-known service and are consistent with the skill's purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external logs and monitors, which could potentially contain untrusted content.
  • Ingestion points: The skill reads output from the Datadog API via curl in SKILL.md and references/windows.md.
  • Boundary markers: There are no explicit markers defined to separate API output from agent instructions.
  • Capability inventory: The agent context includes shell command execution (curl, jq, ConvertFrom-Json).
  • Sanitization: No explicit sanitization or validation of the API response data is documented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:36 PM
Security Audit — agent-trust-hub — datadog