convex-add
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose is coherent for a Convex add-capability skill, and the fallback use of npm/@convex-dev components is proportionate. However, the skill’s primary control path depends on remotely served markdown instructions from a mutable catalog, which creates a meaningful indirect prompt-injection and remote-behavior trust risk even though the endpoint appears to be Convex-hosted.
Confidence: 84%Severity: 64%
Audit Metadata