ai-observability-promptfoo

Warn

Audited by Socket on Sep 20, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/custom-providers.md

The fragment contains legitimate LLM evaluation documentation and CI/CD examples. It does not demonstrate malware or intentional data theft. The primary supply-chain risk is executing npx promptfoo@latest without pinning or integrity verification. Additional security risks include possible exposure of prompts and results through --share, artifacts, and caches, and potential secret misuse when evaluating pull-request-controlled content. Pin the package version, restrict workflows for untrusted forks, minimize permissions, avoid sharing sensitive results, and isolate or validate caches.

Confidence: 93%Severity: 61%
Audit Metadata
Analyzed At
Sep 20, 2026, 03:57 PM
Package URL
pkg:socket/skills-sh/agents-inc%2Fskills%2Fai-observability-promptfoo%2F@40a899cd02f0552c94723f7e6eedbdbed3243fd867bd528c3db8eeddd2c88fbe
Security Audit — socket — ai-observability-promptfoo