install

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose matches its behavior, but it relies on mutable remote content, unpinned npm-executed CLIs, and a postinstall hook that extends agent behavior through transitive trust. This looks more like a risky installer/convenience skill than malware.

Confidence: 87%Severity: 63%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:22 AM
Package URL
pkg:socket/skills-sh/udecode%2Fbetter-convex%2Finstall%2F@a2e74850989c3147312bf0b637b4f9600f4e1027