agent-telemetry

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/dev-endpoint.md

The code is not inherently malware and contains no apparent backdoor or exfiltration logic. It creates a significant information-disclosure risk if reachable outside a trusted development environment because it exposes unredacted logs without authentication. The Next.js startup guard is comparatively strong, while Express and Rails depend on correct environment-based registration. Full-file synchronous processing and weak last/since validation also create denial-of-service and robustness risks. Sensitive data must be redacted before logging, query parameters must be validated, and the endpoint must be structurally excluded from production deployments.

Confidence: 97%Severity: 68%
Audit Metadata
Analyzed At
Sep 17, 2026, 01:25 PM
Package URL
pkg:socket/skills-sh/petekp%2Fagent-skills%2Fagent-telemetry%2F@d62720cb2c6ae9a5a2d253a5036ed5c038d51aab44fd43c2df888a702a6a310c
Security Audit — socket — agent-telemetry