spanora-setup

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/langchain-python.md

The code describes legitimate OpenTelemetry integration, but it intentionally exports detailed LLM and tool telemetry, including potentially sensitive prompts, outputs, metadata, and identifiers, to a third-party endpoint. This represents a meaningful data-disclosure and privacy risk unless the endpoint, retention, access controls, and content-capture settings are trusted and properly configured. No clear malware or backdoor behavior is present in the supplied fragment.

Confidence: 96%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 08:33 AM
Package URL
pkg:socket/skills-sh/spanora%2Fskills%2Fspanora-setup%2F@8b9eb78b3d93c21da443d274507b9b718f6ad6ee46506a38f262b8756d2c600c
Security Audit — socket — spanora-setup