cso
Warn
Audited by Socket on Aug 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core audit behavior is coherent with the skill’s stated security-review purpose, but it includes pre-workflow telemetry and sends metadata to an arbitrary locally configured Convex endpoint, which weakens data-flow integrity. Broad read/Bash/Write access is mostly proportionate for a CSO-style audit, so this is not confirmed malware, but the telemetry design and wide capability footprint raise medium security risk.
Confidence: 86%Severity: 57%
Audit Metadata