apm-observability
Warn
Audited by Socket on Jul 8, 2026
1 alert found:
AnomalyAnomalyreferences/synthetic-monitoring.md
LOWAnomalyLOW
references/synthetic-monitoring.md
No strong indicators of intentional malware or supply-chain sabotage are present in this fragment; it is consistent with synthetic monitoring setup. The primary security concerns are (1) hardcoded plaintext credentials embedded in example configurations/scripts (high risk of accidental leakage), and (2) a private worker design that mounts the host Docker socket, which increases blast radius if the worker runtime/image is compromised. Recommend removing plaintext secrets from examples, using secret stores end-to-end, and minimizing or strictly controlling host-privileged access for private workers.
Confidence: 70%Severity: 63%
Audit Metadata