quickstart

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose mostly matches scaffolding a local Convex app, but its core functionality depends on downloading and executing a remote shell script from an opaque convex.site subdomain and then following a remote runbook as canonical. That creates a significant supply-chain and remote-instruction trust risk, even without clear credential theft or confirmed malicious behavior.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Aug 31, 2026, 02:53 AM
Package URL
pkg:socket/skills-sh/get-convex%2Fconvex-backend-skill%2Fquickstart%2F@cccc1e4cffcff6f6ee4309355c8b6c344fa1eda72c4c64c68c3a1d7ae41b0d10
Security Audit — socket — quickstart