tracekit-apm-setup

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's overall purpose is coherent for an APM onboarding entry point, and public TraceKit docs/packages look same-brand. The main concerns are transitive trust into unseen skills, direct inspection of local auth material, and an opaque auth bootstrap script/flow that can create or sign in accounts and save credentials automatically. No clear malicious exfiltration is shown, but the hidden auth and skill-to-skill chaining make this medium risk rather than benign.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Apr 15, 2026, 12:39 PM
Package URL
pkg:socket/skills-sh/tracekit-dev%2Ftracekit-for-ai%2Ftracekit-apm-setup%2F@2bce4012fabd9de15799336b9c13b2cb4b450c0a