convex

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides implementation patterns for AI chat agents and Retrieval-Augmented Generation (RAG) systems that process untrusted data.
  • Ingestion points: The userMessage parameter in the chat, streamChat, and ragChat actions (documented in references/agents.md) incorporates external text directly into the LLM context.
  • Boundary markers: The provided system prompt examples do not demonstrate the use of delimiters or clear boundary instructions to separate untrusted user context from the model's primary instructions.
  • Capability inventory: The agent patterns described include capabilities to perform database mutations (ctx.runMutation) and execute tools/actions, creating a risk if the agent is manipulated via prompt injection.
  • Sanitization: While the skill utilizes Convex's v validators for type safety, it does not show specific techniques for sanitizing or escaping user-provided text before interpolation into LLM prompts.
  • [SAFE]: The skill demonstrates a strong focus on security best practices for backend development.
  • It mandates authentication checks for public endpoints and provides reusable auth and role-based access control helpers in references/security.md.
  • It enforces the use of internal-only functions (internal.*) for scheduling and cross-function calls to prevent exposing server-side logic to the public API.
  • It emphasizes the use of environment variables for secure management of API keys and secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 12:10 AM