tracekit-java-sdk
Fail
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The TraceKit Java SDK setup skill is broadly coherent with its stated purpose of adding observability/APM to Java applications. It uses environment-based secrets, official package management, framework-specific integration paths, and a verification workflow to ensure traces reach the backend. Data flows are appropriately limited to the observability backend, with no suspicious credential forwarding or outbound data leakage beyond telemetry. While there are normal security considerations around outbound telemetry endpoints, the overall footprint is proportionate to the intended purpose and does not exhibit malicious or oversized permission requirements.
Confidence: 98%
Audit Metadata