convex-audit

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s stated audit purpose is coherent, but it relies on an unverifiable local executable that is not part of Convex’s documented official toolchain. No explicit credential theft or external exfiltration is shown, yet the binary’s opaque provenance creates a high supply-chain risk disproportionate to an otherwise read-first audit workflow.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Mar 19, 2026, 04:56 AM
Package URL
pkg:socket/skills-sh/BjornMelin%2Fdev-skills%2Fconvex-audit%2F@817001099bbb1d6b5fe81db5e59011b5b227ebaa