add-model

Warn

Audited by Socket on Jul 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is mostly aligned with its stated purpose, but it grants an agent authority to edit files, run opaque repo scripts with local API credentials, push directly to main, and trigger/monitor GitHub Actions autonomously. Official tooling lowers supply-chain concern, but the combination of credentialed script execution and autonomous remote actions makes the overall risk medium-high rather than benign.

Confidence: 84%Severity: 71%
Audit Metadata
Analyzed At
Jul 11, 2026, 03:03 PM
Package URL
pkg:socket/skills-sh/get-convex%2Fconvex-evals%2Fadd-model%2F@0ec7e4b1ed69cec9295c47926f00bfe685c7526bc079e2b725c06e03e93e8d55
Security Audit — socket — add-model