tracekit-angular-sdk

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The Angular instrumentation behavior itself is mostly consistent with the stated purpose, but the hidden/opaque auth bootstrap, required transitive tracekit-auth skill, and unreviewed local auth script create trust and credential-handling concerns disproportionate to a normal SDK setup guide. Data flows to the vendor endpoint are plausible, yet optional replay/source-map upload increase sensitivity.

Confidence: 80%Severity: 71%
Audit Metadata
Analyzed At
Apr 15, 2026, 12:39 PM
Package URL
pkg:socket/skills-sh/tracekit-dev%2Ftracekit-for-ai%2Ftracekit-angular-sdk%2F@965ea63de0b1b5e5d0dee1c1062c43c41af71118