apm-observability

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Anomaly
AnomalyLOW
references/synthetic-monitoring.md

No strong indicators of intentional malware or supply-chain sabotage are present in this fragment; it is consistent with synthetic monitoring setup. The primary security concerns are (1) hardcoded plaintext credentials embedded in example configurations/scripts (high risk of accidental leakage), and (2) a private worker design that mounts the host Docker socket, which increases blast radius if the worker runtime/image is compromised. Recommend removing plaintext secrets from examples, using secret stores end-to-end, and minimizing or strictly controlling host-privileged access for private workers.

Confidence: 70%Severity: 63%
Audit Metadata
Analyzed At
Jul 8, 2026, 12:20 PM
Package URL
pkg:socket/skills-sh/j4flmao%2Fagent-skills%2Fapm-observability%2F@c15d9541859aea905de38a64380f1483ba44a8eedfa3a083718db02319c3e3f3
Security Audit — socket — apm-observability