← Blog

What a script tag that clicks for your users can see, send and keep

If you are the developer asked to add Skate to your app, you will ask the same questions every engineer asks about a third-party script. What can it read? What does it send? Who can call it? How do I remove it? This post answers them in the order you would ask.

It repeats what is on our security page and docs, with more detail on how to read it. Skate is in early access. A data processing agreement, a retention policy and a security contact process are being prepared. We will not claim more than that here.

What Skate is

Skate is one script tag. Your user types a task, such as “give Sam editor access”. Skate does it in your real interface, as that user, with that user’s permissions. Before it says done, it reads the page again and checks that the change shows.

<script src="https://api.useskate.com/skate.js" data-site="your-site-id" async></script>

Your dashboard shows your site id and install line after you sign up.

It acts as the user, and only as the user

Skate runs in the user’s own tab. It uses the same session and the same permissions. It does not have a backend login to your system and it does not ask for API keys. If a user cannot do something in your interface, Skate cannot do it for them.

That has a practical effect for you. You do not have to build a second permission model for an assistant. Your existing roles already limit it.

What leaves the page

When a user asks for something, Skate sends our service:

  • the user’s request;
  • the visible controls, labels and text of the current screen;
  • the path, method and status of same-origin requests. Response bodies are off by default.

The service uses that to decide the next step.

What never leaves

These stay in the browser:

  • password, card-number and one-time-code fields;
  • any text that looks like a token or a card number. It is redacted in the browser before anything is sent;
  • cookies, request headers and request bodies;
  • anything inside an element you mark with data-private.

If a screen shows something Skate should never see, add the attribute to that element. It is the quickest way to take a region out of scope, and you can do it in your own templates without asking us.

Where the keys are

The script in your page holds no secrets. Only the origins you register can call the service.

What it will not do on its own

Sends, deletes, payments and anything irreversible wait for the user. The approval card says what will happen, using only what is on the page, such as “Clicking Add to create the task.” An approval covers that one action only. If your app asks the user to type a confirmation, like “type DELETE”, Skate leaves that to the person.

Payment details are never asked for in chat. Online stores and payments are not supported yet.

What it does when it is not sure

Skate says done only when the page shows the result. A partial result is reported as partial. An unconfirmed one is reported as unconfirmed. If a model call times out, the step says so and it is retried once, because nothing has reached the page at that point.

What you control

  • Spend caps per site and per visitor.
  • A session log, and an inbox for results that were flagged as wrong. The owner dashboard shows how each task ended and what visitors needed and did not get.
  • Off switch. Remove the script tag and Skate is gone on the next page load. Or switch your site off in the dashboard, and the service refuses every call from it.

What we keep

Visitor requests and session logs are deleted after 90 days.

What to check before you roll it out

Do not take our word for any of this. Install it on a staging copy and check it yourself:

  1. Open the browser’s network panel and ask Skate for a task. Look at what is sent.
  2. Put a data-private attribute on an element and confirm its text is not in the request.
  3. Ask for a delete and confirm the approval card appears before anything happens.
  4. Register one origin, then call from another and confirm the service refuses.
  5. Remove the tag and confirm the assistant is gone.

If any of that does not match this page, tell us. We would rather fix the page or the product than have you find out later.

Questions we cannot answer yet

We have no completed audit to show you. The DPA is not final.

Questions: write to us.

Try it on your own site.

Sign up free: 500 task credits for your own site, and 10 requests a day to try Skate on any site.

Sign up free