langsmith-fetch

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill document is coherent with its stated purpose: instructing users/agents to install a CLI and fetch LangSmith execution traces using environment-stored API credentials. There are no direct supply-chain red flags in the text (no curl|bash, no untrusted download hosts, no embedded obfuscated payloads). The main security consideration is sensitive: the langsmith-fetch CLI will receive the LANGSMITH_API_KEY and may retrieve sensitive traces — therefore trust in the langsmith-fetch package and its dependencies is required. Recommend users only install the CLI from trusted sources, avoid echoing API keys in shared terminals, and sanitize trace exports before sharing.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 06:48 PM
Package URL
pkg:socket/skills-sh/frostant%2Fawesome-claude-skills%2Flangsmith-fetch%2F@c7efb4617746915a2fe9d963ea284cafae7f6d58