langsmith-trace

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill's stated purpose (LangSmith tracing integration and trace querying/export) is coherent with the described capabilities and data flows. However, the installation approach via a remote curl | sh script from a GitHub raw URL constitutes a notable supply-chain risk and elevates the security risk to suspicious. The credential handling is appropriate for its purpose but warrants secure handling practices. If the installation method is replaced with a verified, pinned, and registry-distributed installer (or a package manager with checksums), and if explicit prompts for data sharing and consent are clarified, the footprint would be considered largely benign for its intended developer tooling purpose.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 01:45 PM
Package URL
pkg:socket/skills-sh/langchain-ai%2Fskills-benchmarks%2Flangsmith-trace%2F@f83882bfdc10c64cb168f8787fe2bf9ad17feed0