tracekit-angular-sdk
Warn
Audited by Socket on Apr 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The Angular instrumentation behavior itself is mostly consistent with the stated purpose, but the hidden/opaque auth bootstrap, required transitive tracekit-auth skill, and unreviewed local auth script create trust and credential-handling concerns disproportionate to a normal SDK setup guide. Data flows to the vendor endpoint are plausible, yet optional replay/source-map upload increase sensitivity.
Confidence: 80%Severity: 71%
Audit Metadata