Official agent skill

Dd Idp

by DataDog in DataDog/pup

Find, filter, count, and connect software, teams, engineering work and delivery, infrastructure, and operational or security records through Pup's read-only Datadog entity graph.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Dd Idp

skills CLI
$ npx skills add DataDog/pup --skill dd-idp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DataDog/pup dd-idp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DataDog/pup.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/dd-idp .claude/skills/dd-idp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dd-idp
GitHub stars
1k
Token cost
~2k tokens
SKILL.md length
834 words
Files
4 (incl. references)
Skills in repo
12
Repo updated
First seen
Licence
Apache-2.0

At a glance

Find, filter, count, and connect software, teams, engineering work and delivery, infrastructure, and operational or security records through Pup's read-only Datadog entity graph.

  • Works in 5 steps: If the relevant kind is unclear, start… → Describe a candidate kind to discover… → Build a small query from the discovered… → …
  • Status questions across connected integrations and custom entities
  • SKILL.md covers Start with the user's question, Choose the right surface, Schema-first workflow and Correctness rules, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Dd Idp is an agent skill from DataDog/pup, published by the product's own GitHub organization. Find, filter, count, and connect software, teams, engineering work and delivery, infrastructure, and operational or security records through Pup's read-only Datadog entity graph. Use for inventory, ownership, dependencies, and status questions across connected integrations and custom entities. Discover available kinds, fields, and relationships progressively when no recipe fits.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/footguns.md`, `references/recipes.md` and `references/ueg-dsl.md`).

It sits in DevOps & Cloud, covering Knowledge graphs. It works with Datadog. The repository describes itself as: Give your AI agent a Pup — a CLI companion with 200+ commands across 33+ Datadog products. The licence is Apache-2.0.

When your agent uses it

  • Status questions across connected integrations and custom entities
  • Tasks that involve Knowledge graphs

Example prompts

  • “/dd-idp”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. If the relevant kind is unclear, start with the curated kind index. If it has
  2. Describe a candidate kind to discover attribute names and types, supported
  3. Build a small query from the discovered schema or adapt a recipe. Scope it to
  4. Inspect warnings and result/relationship truncation. For inventories, use
  5. Synthesize only what the returned fields and declared relations establish. Label noisy matches as inferred and missing edges as unavailable.

What it can do on your machine

Read from SKILL.md and the folder at commit 6a3c662. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dd Idp loads about 2k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 834 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from DataDog/pup at commit 6a3c662, republished under its Apache-2.0 licence (© DataDog). 834 words, ~1,959 tokens.

Download SKILL.mdSave it as .claude/skills/dd-idp/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
dd-idp
description
Find, filter, count, and connect software, teams, engineering work and delivery, infrastructure, and operational or security records through Pup's read-only Datadog entity graph. Use for inventory, ownership, dependencies, and status questions across connected integrations and custom entities. Discover available kinds, fields, and relationships progressively when no recipe fits.
metadata.version
1.0.0
metadata.author
datadog-labs
metadata.repository
https://github.com/DataDog/pup
metadata.tags
datadog,idp,entity-graph,service-catalog,ownership

Datadog IDP Entity Graph

Use Pup's read-only Unified Entity Graph (UEG) to discover software, ownership, work, and operational context. Its main payoff is connected context in one bounded request: a service plus its owners, systems, code, dependencies, and health signals through declared relationships.

Start with the user's question

Use a recipe when one fits. For inventory, ownership, status, or relationship questions about software, infrastructure, or engineering work, check available entity kinds even when no recipe matches. Follow the schema-first workflow, starting from the identifier the user has.

QuestionOften useful toRecipe
Which service handles this endpoint, and who owns it?On-call engineerEndpoint to service
Where is this service's code, and whom should I contact?Engineer joining a teamService context
Who is on call for this service now?Incident leadOn-call contact
Which services depend on this service, database, queue, or provider?SRE or service ownerCaller impact
What does our team own, and what needs attention?Engineering leadPortfolio and health
Which services increased in cost, and where are savings suggested?Engineering lead or FinOps partnerTeam cost
Which services need ownership or standards cleanup?Platform engineerOwnership gaps and scorecard levels
Which public endpoints lack protections, and who owns them?Security engineerAPI posture
Which services and owners need to act on this vulnerability advisory?Security engineerAdvisory to owners
Which Terraform workspaces have drift, and where is their configuration?Platform engineerTerraform drift

Connect resources only through returned relationships; sharing a repository or a similar name does not establish service impact.

Choose the right surface

  • Default to pup idp kinds and pup idp entities query for inventory, ownership, status, or connected context across services, teams, systems, repositories, dependencies, work, operations, or security kinds.
  • Use pup idp assist when the user values a fast, curated single-service summary, metadata gaps, and suggested next actions over graph fidelity; use owner for convenient owner/on-call resolution.
  • Treat find as a simple paginated literal service-name lookup. Explicit kind: and ref: queries remain compatibility paths; use entities query for non-service kinds, another lookback, broader relation families, selected fields, counts, pagination, and traversal. Use deps as a convenient one-hour UEG runtime service-to-service dependency summary.
  • Use product commands such as pup incidents, pup slos, pup monitors, pup logs, pup traces, or pup security when the user needs deeper or current telemetry.
  • Use idp entities facets for observed field values and idp entities aggregate for grouped or filtered counts. Prefer these over paging an inventory just to count it.
  • Use pup service-catalog for the legacy typed service registry and pup software-catalog for Catalog entity/kind reads and writes. Do not use graph queries for mutations.
Show full SKILL.md (419 more words)Show less

Schema-first workflow

  1. If the relevant kind is unclear, start with the curated kind index. If it has no suitable kind, check the live inventory, including custom kinds, before concluding that UEG cannot help:

    bash
    pup --read-only idp kinds list
    pup --read-only idp kinds list --all --include-custom --jq '.kinds | map({kind, display_name})'

    Add --include-low-level when looking for infrastructure kinds such as pods or containers.

  2. Describe a candidate kind to discover attribute names and types, supported filters, and relations with their target kinds:

    bash
    pup --read-only idp kinds describe '<kind>'

    Describe a promising relation's target kind when its fields could help answer the question. Inspect schemas progressively as the investigation needs them.

  3. Build a small query from the discovered schema or adapt a recipe. Scope it to a known identifier or filter, use a small page such as --limit 5, and select only the attributes and relation family needed. Use --fields <kind>=... to select related attributes. Inspect the returned values, then follow returned refs when another hop is useful. Use the query reference to construct queries beyond the examples.

  4. Inspect warnings and result/relationship truncation. For inventories, use an explicit --max-results budget and check page.stop_reason. Continue with next_request.args when completeness is required; see pagination.

  5. Synthesize only what the returned fields and declared relations establish. Label noisy matches as inferred and missing edges as unavailable.

Correctness rules

  • Scope every query with one unquoted kind:<kind> or a concrete ref:"ref:<kind>:<id>".
  • Keep the kind/ref outside alternatives: kind:service AND (owner:payments OR team:payments). A top-level OR is invalid.
  • Never write kind:"service"; the quoted kind silently returns no results upstream and Pup rejects it.
  • --field selects attributes. --include expands relations. Discover both with kinds describe rather than guessing.
  • Use bare terms such as kind:service AND catalog with --free-text-match partial. The mode does not change field filters such as name:*catalog*.
  • Use lookbacks such as 1h, 24h, or 7d for --timeseries-interval. See the DSL reference for absolute windows and property scopes.
  • Treat expanded relations as bounded samples. Increase --relation-limit or query the related kind directly when the full set matters.
  • Treat null or absent counts/booleans as unknown, never as zero or false.
  • Preserve source boundaries: UEG establishes graph facts; product APIs establish detailed operational facts.

References

  • Read UEG DSL when constructing or paginating a query, choosing flags, or following relations.
  • Read UEG footguns when a query fails, unexpectedly returns zero, or touches timestamps, negation, high-cardinality relations, APIs, GitHub, Jira, scorecards, or security findings.
  • Read IDP recipes for runnable queries answering the questions above and other integration workflows.

© DataDog, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/dd-idp of DataDog/pup.

  • SKILL.md
  • references/footguns.md
  • references/recipes.md
  • references/ueg-dsl.md

Open the folder on GitHubat commit 6a3c662

Compare with similar skills

Dd Idp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dd Idp compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dd Idp this skillDataDog/pup1k—~2kAutomated safety check: PassApache-2.0
Apm IntegrationsDataDog/dd-trace-js836—~3kAutomated safety check: PassCustom licence
Datadog Data Source GeneratorDataDog/terraform-provider-datadog468—~2.7kAutomated safety check: PassMPL-2.0
Write RbsDataDog/dd-trace-rb417—~805Automated safety check: PassCustom licence
Apm IntegrationsDataDog/dd-trace-java736—~3.7kAutomated safety check: NotesApache-2.0
Tool ConnectorZhixiangLuo/10xProductivity478—~925Automated safety check: PassMIT

Similar skills

  • Apm Integrations

    DataDog/dd-trace-js

    Official

    A skill your agent uses when adding, debugging, fixing, or modifying instrumentation and plugins for third-party libraries in dd-trace-js.

    836 GitHub stars~3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Datadog Data Source Generator

    DataDog/terraform-provider-datadog

    Official

    Generates a Datadog Terraform provider data source from an OpenAPI operation with tfgen and opens a review-ready GitHub PR with a risk scan and testing guide.

    468 GitHub stars~2.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Write Rbs

    DataDog/dd-trace-rb

    Official

    A skill your agent uses when writing, reviewing, or modifying RBS type signatures (sig//.rbs, vendor/rbs//.rbs, or inline : annotations) or running Steep – e.g.

    417 GitHub stars~805 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Apm Integrations

    DataDog/dd-trace-java

    Official

    Write a new library instrumentation end-to-end. An agent skill from DataDog/dd-trace-java.

    736 GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Tool Connector

    ZhixiangLuo/10xProductivity

    Connect any tool you use at work to your agent — including internal company tools, custom-built systems, deployment portals, incident trackers, internal knowledge bases, HR systems, and commercial…

    478 GitHub stars~925 tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Redis Observability

    redis/agent-skills

    Official

    Redis observability guidance — which metrics to monitor (memory, connections, hit ratio, ops/sec, rejected connections), which built-in commands to reach for during incident triage (SLOWLOG, INFO…

    165 GitHub starsUsed in 2 repos~911 tokens
    DevOps & CloudAuto-check passed

More from DataDog/pup

All 12 skills in this repo
  • Dd Debugger

    DataDog/pup

    Official

    Live Debugger - inspect runtime argument/variable values in production by placing log probes on methods.

    1k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Dd Docs

    DataDog/pup

    Official

    Datadog docs lookup using docs.datadoghq.com/llms.txt and linked Markdown pages.

    1k GitHub starsUsed in 1 repo~558 tokens
    Auto-check passed
  • Pup

    DataDog/pup

    Official

    Datadog API CLI with 49 command groups, 300+ subcommands. An agent skill from DataDog/pup.

    1k GitHub stars~523 tokensUpdated today
    Auto-check passed
  • Official

    Load when investigating a specific flaky test. An agent skill from DataDog/pup.

    1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Dd Apm

    DataDog/pup

    Official

    APM - traces, services, dependencies, performance analysis. An agent skill from DataDog/pup.

    1k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Dd File Issue

    DataDog/pup

    Official

    File GitHub issues to the right repository (pup CLI or plugin)

    1k GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Works with

Questions about Dd Idp

What does Dd Idp do?

Find, filter, count, and connect software, teams, engineering work and delivery, infrastructure, and operational or security records through Pup's read-only Datadog entity graph. Dd Idp is an agent skill from DataDog/pup, published by the product's own GitHub organization. Find, filter, count, and connect software, teams, engineering work and delivery, infrastructure, and operational or security records through Pup's read-only Datadog entity graph.

When should I use Dd Idp?

Dd Idp fits situations like: status questions across connected integrations and custom entities; tasks that involve Knowledge graphs.

How do I install Dd Idp in Claude Code?

Run `npx skills add DataDog/pup --skill dd-idp -a claude-code`. Or copy the skill folder (skills/dd-idp in DataDog/pup) into .claude/skills/dd-idp in your project. Claude Code loads it when a task matches its description.

How do I install Dd Idp in Codex?

Run `npx skills add DataDog/pup --skill dd-idp -a codex`. Or copy the skill folder (skills/dd-idp in DataDog/pup) into .agents/skills/dd-idp in your project. Codex loads it when a task matches its description.

Can I use Dd Idp in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DataDog/pup --skill dd-idp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dd-idp, .gemini/skills/dd-idp, .github/skills/dd-idp and .opencode/skills/dd-idp in your project.

What does Dd Idp need to run?

SKILL.md names no scripts, command-line tools or credentials: Dd Idp is instructions for the agent only.

Does Dd Idp access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Dd Idp safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dd Idp use?

Dd Idp is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dd Idp use?

About 2k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.2k tokens, read only when the agent opens those files.

What are the alternatives to Dd Idp?

Skills that share tags, products or a category with Dd Idp: Apm Integrations (DataDog/dd-trace-js, 836 stars), Datadog Data Source Generator (DataDog/terraform-provider-datadog, 468 stars), Write Rbs (DataDog/dd-trace-rb, 417 stars) and Apm Integrations (DataDog/dd-trace-java, 736 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dd Idp?

DataDog (a GitHub organization, an official publisher) maintains it in DataDog/pup, which has 1,026 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 7, 2026.

Source: DataDog/pup on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.