dt-js-runtime — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited dt-js-runtime (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
The Dynatrace JS runtime is a server-side AppEngine sandbox that executes JavaScript/TypeScript.
Every entry point must export a default async function:
export default async function () {
// ...
return result;
}ES module syntax required. TypeScript accepted (type annotations, interfaces, generics). No other export shape is supported.
Start here, then load only the file you need.
| File | When to load |
|---|---|
| references/limits-and-restrictions.md | Timeout / memory / I/O quotas; what's forbidden (eval, WebSocket, sockets, filesystem) |
| references/apis-and-modules.md | Which Web APIs and Node.js compat modules are available (fetch, crypto, streams, buffer, …) |
| references/fetch.md | Calling internal /platform/... APIs or external URLs, credential vault, outbound allowlist |
| references/sdk.md | Any @dynatrace-sdk/* package — the index routes you to the right per-SDK file |
Use dtctl exec function to run JS runtime code without deploying an app.
# Run inline code
dtctl exec function --code 'export default async function() { return "hello" }'
# Run from file
dtctl exec function -f script.js
# Pass JSON input — accessed as event.payload inside the function
dtctl exec function -f script.js --payload '{"key":"value"}'The function may accept an optional event parameter:
export default async function(event) {
const { payload } = event; // from --payload
// event.environmentId also available
return payload;
}Load the `dynatrace-control` skill for authentication setup, context switching, and the full exec function reference.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.