convos-agent

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The analyzed Convos Agent Skill documentation is internally consistent with its stated purpose. It demonstrates standard install and runtime patterns (npm-based CLI, env production, ndjson streaming) and legitimate integration bridges. No malicious data flows, credential harvesting patterns, or suspicious external endpoints are identified. Overall risk is low to moderate, corresponding to a well-scoped agent management tool rather than a capability with broad or autonomous actions beyond the documented scope.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 08:46 AM
Package URL
pkg:socket/skills-sh/xmtplabs%2Fconvos-skill%2Fconvos-agent%2F@09872675e43414eecd58f9df8f784862253445ff