datawrapper
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses standard shell commands like
catto read a local secret andcurlto make HTTP requests. This usage is transparent and limited to the skill's primary function of interacting with the Datawrapper API. - [DATA_EXFILTRATION]: The skill accesses an API token from
~/.claude-lab/shared/secrets/datawrapper.env. While it transmits this token to an external domain (api.datawrapper.de), this is the official domain for a well-known data visualization service. Accessing and using the credential for its intended service is standard practice and not indicative of malicious exfiltration.
Audit Metadata