tracekit-java-sdk

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The Java APM/instrumentation behavior is broadly aligned with the stated purpose, and the data flow to TraceKit endpoints is plausible for observability. However, the skill expands scope with transitive use of an unreviewed tracekit-auth skill, a referenced local auth script of unknown provenance, automatic credential/bootstrap flow, and optional LLM content capture that can export sensitive prompts and runtime data. Risk is moderate rather than clearly malicious.

Confidence: 79%Severity: 64%
Audit Metadata
Analyzed At
Apr 15, 2026, 12:37 PM
Package URL
pkg:socket/skills-sh/tracekit-dev%2Ftracekit-for-ai%2Ftracekit-java-sdk%2F@c9a17dacdfc15eef8ef51738331d8c3b3a3167fa