tracekit-nuxt-sdk

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill content is coherent with its stated purpose of guiding a developer to integrate TraceKit into a Nuxt 3 project. It uses standard, trusted sources (npm registry) and maintains a scoped data flow (client-side tracing data to the TraceKit service). The main risk is the exposure of a public API key on the client via runtimeConfig, which is typical for browser-based SDKs but should be restricted to a public-facing key rather than a secret. Overall, the footprint is proportionate and aligns with legitimate developer tooling for observability. No evidence of credential harvesting, unintended data exfiltration to unknown endpoints, or supply-chain exploitation is detected. Recommend proceeding with caution around key exposure and enforcing environment-based key management.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:42 PM
Package URL
pkg:socket/skills-sh/tracekit-dev%2Ftracekit-for-ai%2Ftracekit-nuxt-sdk%2F@d1efc75e2adfd2c3a4ec3a6af3d9e9111f352dee