observability

Warn

Audited by Socket on Sep 11, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
evals/files/prod-incident-signals.md

The incident evidence indicates severe observability cardinality explosion, poor log-trace correlation, order-specific trace naming, and under-sampled traces. Prometheus instability and misleading graphs are likely consequences. The emergency labeldrop rule is incomplete and may distort metric identity and rate calculations; it does not demonstrate recovery or fully stop cardinality growth. No malicious behavior is present in the supplied incident material.

Confidence: 96%Severity: 62%
AnomalyLOW
evals/files/checkout-telemetry.ts

The code appears to implement legitimate checkout telemetry and payment processing, with no clear evidence of malware or intentional sabotage. The main security concerns are transmission and possible telemetry capture of raw card data, trusting a client-supplied user ID, excessive sensitive/high-cardinality metric labels, and failure to validate the provider response. The shown database operations are parameterized and do not expose an evident SQL injection path.

Confidence: 94%Severity: 67%
Audit Metadata
Analyzed At
Sep 11, 2026, 03:16 PM
Package URL
pkg:socket/skills-sh/lynricsy%2Fhyperskills%2Fobservability%2F@48150db0b2ffcf61c4701b528d5a6a593194ce5d303d18eb6bdae94d4c21805e
Security Audit — socket — observability