litellm

Warn

Audited by Socket on Aug 22, 2026

1 alert found:

Security
SecurityMEDIUM
references/proxy-config.md

No overt malicious code is identifiable because the provided fragment is configuration/deployment content. However, it contains multiple high-impact security misconfiguration signals: hardcoded sensitive values in config.yaml (master key, database credentials, Redis password), weak/default credentials in Docker Compose examples, and plaintext secret injection via Helm command-line flags. Additionally, telemetry callbacks (Langfuse/Sentry) are configured, which can widen data exposure risk depending on what data those integrations emit. Overall, treat this as a significant credential-handling and data-exposure risk requiring remediation (move secrets to proper secret stores, remove inline secrets from config examples, avoid --set for secrets, enforce telemetry/data minimization).

Confidence: 74%Severity: 78%
Audit Metadata
Analyzed At
Aug 22, 2026, 10:39 AM
Package URL
pkg:socket/skills-sh/kettleofketchup%2Fkettleofskills%2Flitellm%2F@47671fd02a3a420ae806e916a3c8c43a14119dbe1198b41ac43a1e480306bba1
Security Audit — socket — litellm