Back to skill

Security audit

Datadog

Security checks across malware telemetry and agentic risk

Overview

This appears to be a Datadog integration skill with one scoping issue to watch, but no evidence of malware, hidden persistence, or deceptive behavior.

Before installing, confirm you want the agent to use this skill for Datadog-related work and prefer explicit confirmation before creating, editing, or deleting Datadog resources such as monitors, dashboards, incidents, or configuration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill explicitly claims it should be used for "ANY Datadog request" and whenever a task involves Datadog, which creates an overly broad routing rule. This can cause the agent to invoke the skill in contexts where direct API use, narrower tooling, or additional user confirmation would be more appropriate, increasing the chance of unintended data access or execution paths.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.