tracekit-apm-setup
Pass
Audited by Gen Agent Trust Hub on Apr 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses a local script
./scripts/run-tracekit-auth.shto check the current authentication status. This is a legitimate vendor-provided utility for project initialization.\n- [DATA_EXFILTRATION]: The skill accesses the configuration file~/.tracekitconfigand theTRACEKIT_API_KEYenvironment variable. This access is limited to the vendor's own authentication data required for the service to function.\n- [SAFE]: The technology stack is identified by scanning project manifest files likepackage.json,go.mod, andrequirements.txt. This is a common and expected behavior for developer tools and does not pose a security threat in this context.\n- [SAFE]: The instruction to prioritize thetracekit-authskill over manual signup flows is a user experience optimization. The process remains transparent as it involves a standard email verification step and does not attempt to bypass security controls.
Audit Metadata