tracekit-alerts

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core alerting behavior is largely coherent and official: tokens go to TraceKit’s own API and dashboard, and Slack/webhook/PagerDuty integrations fit the purpose. The main concerns are the forced dependency on another auth skill, the opaque local helper script for auth/bootstrap, and transitive skill installation trust. This is not strong evidence of malware or credential theft, but it is higher-risk than a self-contained documentation-only skill.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
Apr 15, 2026, 12:37 PM
Package URL
pkg:socket/skills-sh/tracekit-dev%2Ftracekit-for-ai%2Ftracekit-alerts%2F@f9aa7bb36fe56d0904d1716257367640f986cc45