convex-add

Warn

Audited by Socket on Aug 12, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose is coherent, but its main control path depends on mutable remote markdown from a .convex.site endpoint that the agent is instructed to follow. That creates a high indirect prompt-injection and execution-trust risk even without visible credential theft or explicit malware behavior.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Aug 12, 2026, 03:16 PM
Package URL
pkg:socket/skills-sh/get-convex%2Ftemplates%2Fconvex-add%2F@6ce9c2df685fb088eb85f026078cca6b3547ca7322062a5309e7fdf4b199189c
Security Audit — socket — convex-add