tracekit-dotnet-sdk
Warn
Audited by Socket on Apr 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is mostly coherent for an observability SDK, but it is not purely a local .NET integration guide: it reads local auth state, invokes a separate auth skill/script, and automates account bootstrap. Data flows to TraceKit endpoints are consistent with APM, yet optional LLM content capture and mandatory code monitoring increase sensitivity. Overall this is suspicious rather than malicious due to transitive-skill dependency and credential/bootstrap scope beyond basic SDK setup.
Confidence: 81%Severity: 58%
Audit Metadata