observability

Warn

Audited by Socket on May 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s monitoring purpose is plausible, but it relies on external CLI binaries whose exact provenance is not verifiable from the evidence and grants broad execution through them. Data collection is mostly consistent with observability, yet backend process attachment, tracepoint injection, and arbitrary OTEL export destinations increase exposure. High security risk is driven primarily by the unverifiable required CLIs rather than confirmed malicious behavior.

Confidence: 82%Severity: 78%
Audit Metadata
Analyzed At
May 29, 2026, 01:39 AM
Package URL
pkg:socket/skills-sh/ironbee-ai%2Fironbee-devtools-skills%2Fobservability%2F@71ed988c517e10cbe7f497a4a1af24cfe30ba467
Security Audit — socket — observability