datadog-cli
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, but its trust model is not. It instructs the agent to execute a non-official-looking third-party Datadog CLI via npx and forward powerful Datadog credentials to it, creating a high supply-chain and credential-harvesting risk without proof of Datadog ownership or verified release provenance.
Confidence: 89%Severity: 83%
Audit Metadata