datawrapper

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses standard shell commands like cat to read a local secret and curl to make HTTP requests. This usage is transparent and limited to the skill's primary function of interacting with the Datawrapper API.
  • [DATA_EXFILTRATION]: The skill accesses an API token from ~/.claude-lab/shared/secrets/datawrapper.env. While it transmits this token to an external domain (api.datawrapper.de), this is the official domain for a well-known data visualization service. Accessing and using the credential for its intended service is standard practice and not indicative of malicious exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 11:13 AM
Security Audit — agent-trust-hub — datawrapper