convex-add

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is coherent for a Convex add-capability skill, and the fallback use of npm/@convex-dev components is proportionate. However, the skill’s primary control path depends on remotely served markdown instructions from a mutable catalog, which creates a meaningful indirect prompt-injection and remote-behavior trust risk even though the endpoint appears to be Convex-hosted.

Confidence: 84%Severity: 64%
Audit Metadata
Analyzed At
Aug 4, 2026, 05:29 PM
Package URL
pkg:socket/skills-sh/get-convex%2Fagent-skills%2Fconvex-add%2F@6ce9c2df685fb088eb85f026078cca6b3547ca7322062a5309e7fdf4b199189c
Security Audit — socket — convex-add