Skip to content

chore(deps): update datadog-labs/agent-skills digest to 75c9261 - #675

Open
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/datadog-labs-agent-skills-digest
Open

chore(deps): update datadog-labs/agent-skills digest to 75c9261#675
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/datadog-labs-agent-skills-digest

Conversation

@renovate

@renovate renovate Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
datadog-labs/agent-skills digest 9bcb3ce75c9261

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@toolhive-release-app

toolhive-release-app Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

🛡️ Skill Security Scan Results

✅ agent-observability-eval-bootstrap

  • Status: Passed
  • Findings: 483
  • Allowed (not blocking): 480
    • LLM_PROMPT_INJECTION (Allowed: FP: same as policy_violation above — all pattern matches are on documentation, code examples, or attack pattern descriptions for detection purposes, not agent instructions.)
    • MANIFEST_MISSING_LICENSE (Allowed: datadog-labs/agent-skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00040 (Allowed: FP: matched the word 'Deploy' in prose 'Deploy to Datadog LLM Experiments' (SKILL.md:729). Documentation step, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00040 (Allowed: FP: matched the word 'Deploy' in prose 'Deploy to Datadog LLM Experiments' (SKILL.md:729). Documentation step, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00040 (Allowed: FP: matched the word 'Deploy' in prose 'Deploy to Datadog LLM Experiments' (SKILL.md:729). Documentation step, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00061 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00040 (Allowed: FP: matched the word 'Deploy' in prose 'Deploy to Datadog LLM Experiments' (SKILL.md:729). Documentation step, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • PG_PII_SSN_HARVESTING (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00061 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00213 (Allowed: FP: matched the literal words 'system prompt' / 'System Prompt' in prose describing Datadog span fields and eval dimensions. Documentation, not a system-prompt-extraction attack. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00020 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00062 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00062 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00213 (Allowed: FP: matched the literal words 'system prompt' / 'System Prompt' in prose describing Datadog span fields and eval dimensions. Documentation, not a system-prompt-extraction attack. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00051 (Allowed: FP: matched the prose phrase 'For each' (loop-over-traces guidance). Documentation, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00063 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00213 (Allowed: FP: matched the literal words 'system prompt' / 'System Prompt' in prose describing Datadog span fields and eval dimensions. Documentation, not a system-prompt-extraction attack. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00061 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00061 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00213 (Allowed: FP: matched the literal words 'system prompt' / 'System Prompt' in prose describing Datadog span fields and eval dimensions. Documentation, not a system-prompt-extraction attack. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00001 (Allowed: FP: matched prose 'these become the domain-specific evaluator category' (SKILL.md:371). Documentation guidance, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00090 (Allowed: FP: matched prose 'Extract the rules implicitly followed across observed outputs' (SKILL.md:375). Analysis guidance, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00118 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00032 (Allowed: FP: matched prose 'skip this step and proceed directly' (SKILL.md:396). Workflow instruction, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00213 (Allowed: FP: matched the literal words 'system prompt' / 'System Prompt' in prose describing Datadog span fields and eval dimensions. Documentation, not a system-prompt-extraction attack. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00110 (Allowed: FP: matched eval ( inside an example Python evaluator function signature. Not a code-eval sink. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00051 (Allowed: FP: matched the prose phrase 'For each' (loop-over-traces guidance). Documentation, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00051 (Allowed: FP: matched the prose phrase 'For each' (loop-over-traces guidance). Documentation, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • PG_EXFIL_MARKDOWN_LINK (Allowed: False positive - the flagged pattern is a markdown link template
      [Trace {first_8}...](https://app.datadoghq.com/llm/traces?query=trace_id:{full_32_char_id})
      used by the skill to cite trace evidence to the USER. The destination
      (app.datadoghq.com) is the user's own Datadog SaaS tenant; the encoded
      value is a trace_id surfaced from the user's own LLM Observability data
      — not exfiltrated agent context. The link is rendered for the user to
      click and verify the cited trace, which is the explicit purpose stated
      in the "Show your work" operating rule. Verified at digest
      98343f304cbd4439b3d7640cfe64f78070e44d68 (SKILL.md:681).
      )
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00051 (Allowed: FP: matched the prose phrase 'For each' (loop-over-traces guidance). Documentation, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00213 (Allowed: FP: matched the literal words 'system prompt' / 'System Prompt' in prose describing Datadog span fields and eval dimensions. Documentation, not a system-prompt-extraction attack. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00030 (Allowed: FP: matched run() (SKILL.md:613) inside an example Python experiment-client snippet. Not an attack vector. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00051 (Allowed: FP: matched the prose phrase 'For each' (loop-over-traces guidance). Documentation, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00040 (Allowed: FP: matched the word 'Deploy' in prose 'Deploy to Datadog LLM Experiments' (SKILL.md:729). Documentation step, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00061 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00004 (Allowed: FP: matched JSON/code example fragment {role: " in an eval message schema. Documentation/code, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00213 (Allowed: FP: matched the literal words 'system prompt' / 'System Prompt' in prose describing Datadog span fields and eval dimensions. Documentation, not a system-prompt-extraction attack. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00213 (Allowed: FP: matched the literal words 'system prompt' / 'System Prompt' in prose describing Datadog span fields and eval dimensions. Documentation, not a system-prompt-extraction attack. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00091 (Allowed: FP: matched literal \n newline escapes inside JSON/code example blocks. Documentation/code, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00091 (Allowed: FP: matched literal \n newline escapes inside JSON/code example blocks. Documentation/code, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00091 (Allowed: FP: matched literal \n newline escapes inside JSON/code example blocks. Documentation/code, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00091 (Allowed: FP: matched literal \n newline escapes inside JSON/code example blocks. Documentation/code, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00213 (Allowed: FP: matched the literal words 'system prompt' / 'System Prompt' in prose describing Datadog span fields and eval dimensions. Documentation, not a system-prompt-extraction attack. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00091 (Allowed: FP: matched literal \n newline escapes inside JSON/code example blocks. Documentation/code, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00091 (Allowed: FP: matched literal \n newline escapes inside JSON/code example blocks. Documentation/code, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00091 (Allowed: FP: matched literal \n newline escapes inside JSON/code example blocks. Documentation/code, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00091 (Allowed: FP: matched literal \n newline escapes inside JSON/code example blocks. Documentation/code, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00040 (Allowed: FP: matched the word 'Deploy' in prose 'Deploy to Datadog LLM Experiments' (SKILL.md:729). Documentation step, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00051 (Allowed: FP: matched the prose phrase 'For each' (loop-over-traces guidance). Documentation, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00051 (Allowed: FP: matched the prose phrase 'For each' (loop-over-traces guidance). Documentation, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00051 (Allowed: FP: matched the prose phrase 'For each' (loop-over-traces guidance). Documentation, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00061 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00118 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00118 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00118 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • PG_EXFIL_MARKDOWN_LINK (Allowed: False positive - the flagged pattern is a markdown link template
      [Trace {first_8}...](https://app.datadoghq.com/llm/traces?query=trace_id:{full_32_char_id})
      used by the skill to cite trace evidence to the USER. The destination
      (app.datadoghq.com) is the user's own Datadog SaaS tenant; the encoded
      value is a trace_id surfaced from the user's own LLM Observability data
      — not exfiltrated agent context. The link is rendered for the user to
      click and verify the cited trace, which is the explicit purpose stated
      in the "Show your work" operating rule. Verified at digest
      98343f304cbd4439b3d7640cfe64f78070e44d68 (SKILL.md:681).
      )
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00111 (Allowed: FP: word-fragment matches — summarizing a policy (example intent category), eval_scope (identifier). Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00066 (Allowed: FP: matched Datadog eval-prompt template placeholders — {{input_data}}, {{output_data}}, {{span_input}}, {{meta.input.messages[*].content}}. These are the documented templating syntax for LLM-judge prompts, not injected payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00010 (Allowed: FP: matched backtick-wrapped upstream tool/CLI names — get_llmobs_evaluator, list_llmobs_eval*, create_or_update_llmobs_eval*, pup llm-obs evals get-eval, /eval. Documentation references to tools the skill instructs the agent to call against the user's own Datadog tenant, not executed payloads. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00012 (Allowed: FP: word-fragment matches — integration_account_id, table cells, tool-name fragments like get_llmobs_span_details(trace_id. Documentation strings, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00091 (Allowed: FP: matched literal \n newline escapes inside JSON/code example blocks. Documentation/code, no executable threat. datadog-labs/agent-skills @9bcb3ce.)
    • ATR_2026_00099 (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • LLM_CONTEXT_BUDGET_EXCEEDED (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)
    • LLM_CONTEXT_BUDGET_EXCEEDED (Allowed: FP: agent-observability-eval-bootstrap is a Datadog LLM Observability documentation skill. All ATR pattern matches are on evaluation setup documentation, Python evaluator code examples, and Datadog API reference material — not agent instructions.)

✅ agent-observability-experiment-analyzer

  • Status: Passed
  • Findings: 3
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: datadog-labs/agent-skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ agent-observability-session-classify

  • Status: Passed
  • Findings: 3
  • Allowed (not blocking): 2
    • LLM_CONTEXT_BUDGET_EXCEEDED (Allowed: FP: agent-observability-session-classify is a Datadog Agent Observability documentation skill. All ATR pattern matches are on evaluation and tracing documentation, and Datadog API reference material — not agent instructions.)
    • LLM_CONTEXT_BUDGET_EXCEEDED (Allowed: FP: agent-observability-session-classify is a Datadog Agent Observability documentation skill. All ATR pattern matches are on evaluation and tracing documentation, and Datadog API reference material — not agent instructions.)

✅ agent-observability-trace-rca

  • Status: Passed
  • Findings: 3
  • Allowed (not blocking): 1
    • LLM_PROMPT_INJECTION (Allowed: FP: same as policy_violation above — all pattern matches are on documentation, code examples, or attack pattern descriptions for detection purposes, not agent instructions.)

✅ dd-apm

  • Status: Passed
  • Findings: 8
  • Allowed (not blocking): 4
    • MANIFEST_MISSING_LICENSE (Allowed: datadog-labs/agent-skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)
    • COMPOUND_EXTRACT_EXECUTE (Allowed: FP: cisco-ai-skill-scanner matched the documented pup CLI install
      snippet in k8s-ssi/agent-install/SKILL.md:67,
      k8s-ssi/troubleshoot-ssi/SKILL.md:48 and
      linux-ssi/troubleshoot-ssi/SKILL.md:48. The snippet downloads the
      official pup release tarball from the same vendor
      (github.com/datadog-labs/pup/releases, version pinned via the GitHub
      releases API) and pipes it through tar xz into /usr/local/bin — the
      canonical, vendor-published CLI install instruction shown to the user,
      not a hidden/malicious archive payload. No executable threat.
      datadog-labs/agent-skills @9bcb3ceafacae78dbba76c9459a878fc7d6a0d10.
      )
    • COMPOUND_EXTRACT_EXECUTE (Allowed: FP: cisco-ai-skill-scanner matched the documented pup CLI install
      snippet in k8s-ssi/agent-install/SKILL.md:67,
      k8s-ssi/troubleshoot-ssi/SKILL.md:48 and
      linux-ssi/troubleshoot-ssi/SKILL.md:48. The snippet downloads the
      official pup release tarball from the same vendor
      (github.com/datadog-labs/pup/releases, version pinned via the GitHub
      releases API) and pipes it through tar xz into /usr/local/bin — the
      canonical, vendor-published CLI install instruction shown to the user,
      not a hidden/malicious archive payload. No executable threat.
      datadog-labs/agent-skills @9bcb3ceafacae78dbba76c9459a878fc7d6a0d10.
      )
    • COMPOUND_EXTRACT_EXECUTE (Allowed: FP: cisco-ai-skill-scanner matched the documented pup CLI install
      snippet in k8s-ssi/agent-install/SKILL.md:67,
      k8s-ssi/troubleshoot-ssi/SKILL.md:48 and
      linux-ssi/troubleshoot-ssi/SKILL.md:48. The snippet downloads the
      official pup release tarball from the same vendor
      (github.com/datadog-labs/pup/releases, version pinned via the GitHub
      releases API) and pipes it through tar xz into /usr/local/bin — the
      canonical, vendor-published CLI install instruction shown to the user,
      not a hidden/malicious archive payload. No executable threat.
      datadog-labs/agent-skills @9bcb3ceafacae78dbba76c9459a878fc7d6a0d10.
      )

✅ dd-docs

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: datadog-labs/agent-skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ dd-logs

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: datadog-labs/agent-skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ dd-monitors

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: datadog-labs/agent-skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ dd-pup

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: datadog-labs/agent-skills is licensed MIT at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

Summary: Scanned 9 skill(s), all passed security checks. ✅

@renovate renovate Bot changed the title chore(deps): update datadog-labs/agent-skills digest to 9dbf79d chore(deps): update datadog-labs/agent-skills digest to 66c3d94 Jul 2, 2026
@renovate
renovate Bot force-pushed the renovate/datadog-labs-agent-skills-digest branch 2 times, most recently from 6bf01d2 to 478a7ee Compare July 3, 2026 10:17
@renovate renovate Bot changed the title chore(deps): update datadog-labs/agent-skills digest to 66c3d94 chore(deps): update datadog-labs/agent-skills digest to 69cca0e Jul 27, 2026
@renovate
renovate Bot force-pushed the renovate/datadog-labs-agent-skills-digest branch from 22cc463 to d2886f1 Compare July 27, 2026 09:42
@renovate renovate Bot changed the title chore(deps): update datadog-labs/agent-skills digest to 69cca0e chore(deps): update datadog-labs/agent-skills digest to 75c9261 Jul 29, 2026
@renovate
renovate Bot force-pushed the renovate/datadog-labs-agent-skills-digest branch from 0eaeb66 to 427cf1c Compare July 29, 2026 06:54
…ap,agent-observability-experiment-analyzer,agent-observability-session-classify,agent-observability-trace-rca,dd-apm,dd-docs,dd-logs,dd-monitors,dd-pup
@renovate

renovate Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants