labs-quickstart
Warn
Audited by Socket on Jul 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's purpose and capabilities mostly align with a Convex quickstart/publish workflow, and its endpoints are consistent with Convex infrastructure, but it relies on several undocumented mutable remote scripts executed locally, including a curl|bash reporting path. This is not confirmed malware, yet the install/execution trust and opaque server-side bootstrap logic make it a high security-risk skill.
Confidence: 86%Severity: 76%
Audit Metadata