copilot-otel-metrics

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SECURITY.md

This is a security assessment document for an observability integration, not malicious executable package code. It openly describes substantial privacy and security risks: prompt-bearing telemetry, plaintext local transport, persistent unencrypted traces, unauthenticated local APIs, shared fleet credentials, unsupported telemetry carriers, and an unprobed gRPC path. Those risks warrant review if the described system is implemented, but the fragment itself shows no malware behavior, code execution, data theft routine, or suspicious external destination. Conclusions about the referenced scripts and configurations remain limited because their implementations are outside the supplied fragment.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 11, 2026, 06:29 PM
Package URL
pkg:socket/skills-sh/microsoft%2Fhve-core%2Fcopilot-otel-metrics%2F@99818096e8e3b7f12454445bdb85ef7cd8d56226473edaa701162ffb82a033cf
Security Audit — socket — copilot-otel-metrics