convex-feature-spec

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s planning purpose is plausible, but it relies on an unverifiable local binary not documented as part of the official Convex CLI. There is no explicit credential theft or confirmed exfiltration in the visible instructions, but execution of opaque support tooling against a repo creates high supply-chain risk disproportionate to a documentation/spec skill.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
Mar 19, 2026, 04:56 AM
Package URL
pkg:socket/skills-sh/BjornMelin%2Fdev-skills%2Fconvex-feature-spec%2F@fe6b57da645f79bb2dd94da2d25dc66ed0889b08