quickstart
Warn
Audited by Socket on Aug 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose mostly matches scaffolding a local Convex app, but its core functionality depends on downloading and executing a remote shell script from an opaque convex.site subdomain and then following a remote runbook as canonical. That creates a significant supply-chain and remote-instruction trust risk, even without clear credential theft or confirmed malicious behavior.
Confidence: 84%Severity: 72%
Audit Metadata