tracekit-react-sdk

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core purpose is coherent for a React APM skill and its network destination matches the claimed TraceKit service, but trust is weakened by the required unreviewed tracekit-auth skill, local credential-file checks, and unverified provenance for the React/replay packages and tracekit CLI in the provided evidence. This looks more like a legitimate-but-underverified vendor integration than clear malware.

Confidence: 83%Severity: 62%
Audit Metadata
Analyzed At
Apr 15, 2026, 12:39 PM
Package URL
pkg:socket/skills-sh/tracekit-dev%2Ftracekit-for-ai%2Ftracekit-react-sdk%2F@e3bd81ee9865df19cb6ed8d44641a1987113ad06
Security Audit — socket — tracekit-react-sdk