labs-quickstart

Warn

Audited by Socket on Jul 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities mostly align with a Convex quickstart/publish workflow, and its endpoints are consistent with Convex infrastructure, but it relies on several undocumented mutable remote scripts executed locally, including a curl|bash reporting path. This is not confirmed malware, yet the install/execution trust and opaque server-side bootstrap logic make it a high security-risk skill.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Jul 17, 2026, 08:26 PM
Package URL
pkg:socket/skills-sh/get-convex%2Fconvex-backend-skill%2Flabs-quickstart%2F@9abb0cedcdd024e7f80cf7bb814f04ba525e1f1e93de7c3d154cc0ee20c6978f
Security Audit — socket — labs-quickstart