tracekit-nuxt-sdk

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Suspicious rather than clearly malicious. The Nuxt instrumentation, npm install path, and app.tracekit.dev telemetry endpoint are broadly consistent with an APM SDK, but the skill overreaches by chaining into an unreviewed auth skill/local script, minimizing user awareness during account/auth setup, and forwarding credentials to a CLI with limited provenance evidence.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 15, 2026, 12:39 PM
Package URL
pkg:socket/skills-sh/tracekit-dev%2Ftracekit-for-ai%2Ftracekit-nuxt-sdk%2F@5aebcbbb8580935a2edb7e5f28b2f84aa4b2f82d