datadog-automation
Pass
Audited by Gen Agent Trust Hub on Mar 5, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs users to connect to a remote MCP server at
https://rube.app/mcpto access the Datadog tools. This is the intended source of tool definitions.\n- [PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it retrieves and processes external content from Datadog logs and events.\n - Ingestion points: Data from Datadog is ingested via
DATADOG_SEARCH_LOGS,DATADOG_LIST_EVENTS, and other search/query tools.\n - Boundary markers: There are no explicit instructions or delimiters defined to prevent the agent from executing instructions embedded in the retrieved Datadog data.\n
- Capability inventory: The skill provides destructive and modification capabilities such as
DATADOG_DELETE_DASHBOARD,DATADOG_UPDATE_MONITOR, andDATADOG_CREATE_EVENT.\n - Sanitization: No sanitization or content validation logic is described for the data fetched from the external Datadog environment.
Audit Metadata