monitoring

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core monitoring capabilities are mostly aligned with the stated observability purpose and rely on official ecosystems, so this is not clearly malicious. However, the skill is over-privileged for an autonomous agent: it scans broadly, edits application and infrastructure files, runs deployment-validation commands, and silently writes telemetry into a user memory directory outside the repo. Vendor integrations like Datadog/New Relic are legitimate but introduce credential-handling and third-party data flow risk. Overall this is a coherent devops skill with meaningful autonomy and local data-write risk, not a credential-harvesting or exfiltration skill.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fmonitoring%2F@ae0c824f7f84ef76d30cf769381f8151994ba70a
Security Audit — socket — monitoring