quickstart

Warn

Audited by Socket on Jul 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is plausible, but the implementation relies on executing a remotely fetched bootstrap and following a mutable remote runbook from an unverifiable hosted endpoint, while also sending user idea data as telemetry. That footprint is disproportionate to a local app quickstart and creates high supply-chain and remote-instruction risk even though the underlying Convex/Next.js goal is legitimate.

Confidence: 91%Severity: 90%
Audit Metadata
Analyzed At
Jul 17, 2026, 08:26 PM
Package URL
pkg:socket/skills-sh/get-convex%2Fconvex-backend-skill%2Fquickstart%2F@730ad9ba8d02117b9c6e0923b545e448cdd2b8e6ca9e899f654e1688ba7c2f48
Security Audit — socket — quickstart