convex-design
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill recommends installing official platform components from the
@convex-devorganization on NPM, such as@convex-dev/agent,@convex-dev/workflow, and@convex-dev/rag. These are established libraries provided for building applications on Convex. - [COMMAND_EXECUTION]: The skill instructs the agent to use legitimate platform CLI tools for development workflows, including
npx convex devfor the development loop andnpx @convex-dev/authfor authentication configuration. - [COMMAND_EXECUTION]: The skill suggests running
npx convex mcp startto initialize a Model Context Protocol server. This allows the agent to introspect the project's deployment metadata, schemas, and logs to improve development accuracy.
Audit Metadata