labs-quickstart
Warn
Audited by Socket on Aug 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose is coherent, and consent is requested before public publishing or transcript submission, but its actual footprint relies heavily on remote download-and-execute from a specific convex.site deployment plus remote telemetry/runbook control. This is proportionate to a bootstrap/publish workflow, yet the install/execution trust is high-risk enough to classify the skill as suspicious rather than benign.
Confidence: 83%Severity: 78%
Audit Metadata