tracekit-nextjs-sdk

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior is mostly coherent for a Next.js observability integration and data flows go to same-brand TraceKit endpoints, but trust is weakened by the undocumented local auth script, the requirement to invoke another skill first, and only partial verification of the exact SDK/CLI publication path. This looks more like a legitimate-but-medium-risk vendor setup skill than clear malware.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 15, 2026, 12:39 PM
Package URL
pkg:socket/skills-sh/tracekit-dev%2Ftracekit-for-ai%2Ftracekit-nextjs-sdk%2F@00128f0afc4ef6034055ae54497fc3bb64e3f170