tracekit-apm-setup
Warn
Audited by Socket on Apr 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's overall purpose is coherent for an APM onboarding entry point, and public TraceKit docs/packages look same-brand. The main concerns are transitive trust into unseen skills, direct inspection of local auth material, and an opaque auth bootstrap script/flow that can create or sign in accounts and save credentials automatically. No clear malicious exfiltration is shown, but the hidden auth and skill-to-skill chaining make this medium risk rather than benign.
Confidence: 84%Severity: 62%
Audit Metadata