datocms-cma
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill exclusively utilizes official, verified packages from the vendor (@datocms/cma-client-node, @datocms/cma-client, etc.) and well-known developer utilities like dotenv-cli.
- [SAFE]: Authentication security is a priority, with instructions favoring OAuth-based CLI sessions and environment-variable storage for API tokens while explicitly warning against hardcoding credentials.
- [SAFE]: The skill promotes defensive development practices, such as requiring explicit user confirmation before linking projects and using isolated sandbox environments for schema mutations to prevent accidental production data loss.
Audit Metadata