tracekit-nuxt-sdk
Warn
Audited by Socket on Apr 15, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Suspicious rather than clearly malicious. The Nuxt instrumentation, npm install path, and app.tracekit.dev telemetry endpoint are broadly consistent with an APM SDK, but the skill overreaches by chaining into an unreviewed auth skill/local script, minimizing user awareness during account/auth setup, and forwarding credentials to a CLI with limited provenance evidence.
Confidence: 87%Severity: 72%
Audit Metadata