convex
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides implementation patterns for AI chat agents and Retrieval-Augmented Generation (RAG) systems that process untrusted data.
- Ingestion points: The
userMessageparameter in thechat,streamChat, andragChatactions (documented inreferences/agents.md) incorporates external text directly into the LLM context. - Boundary markers: The provided system prompt examples do not demonstrate the use of delimiters or clear boundary instructions to separate untrusted user context from the model's primary instructions.
- Capability inventory: The agent patterns described include capabilities to perform database mutations (
ctx.runMutation) and execute tools/actions, creating a risk if the agent is manipulated via prompt injection. - Sanitization: While the skill utilizes Convex's
vvalidators for type safety, it does not show specific techniques for sanitizing or escaping user-provided text before interpolation into LLM prompts. - [SAFE]: The skill demonstrates a strong focus on security best practices for backend development.
- It mandates authentication checks for public endpoints and provides reusable auth and role-based access control helpers in
references/security.md. - It enforces the use of internal-only functions (
internal.*) for scheduling and cross-function calls to prevent exposing server-side logic to the public API. - It emphasizes the use of environment variables for secure management of API keys and secrets.
Audit Metadata