tracekit-apm-setup

Pass

Audited by Gen Agent Trust Hub on Apr 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses a local script ./scripts/run-tracekit-auth.sh to check the current authentication status. This is a legitimate vendor-provided utility for project initialization.\n- [DATA_EXFILTRATION]: The skill accesses the configuration file ~/.tracekitconfig and the TRACEKIT_API_KEY environment variable. This access is limited to the vendor's own authentication data required for the service to function.\n- [SAFE]: The technology stack is identified by scanning project manifest files like package.json, go.mod, and requirements.txt. This is a common and expected behavior for developer tools and does not pose a security threat in this context.\n- [SAFE]: The instruction to prioritize the tracekit-auth skill over manual signup flows is a user experience optimization. The process remains transparent as it involves a standard email verification step and does not attempt to bypass security controls.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 15, 2026, 12:37 PM