convex-domains
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to utilize existing authenticated command-line interfaces such as flarectl, aws, gcloud, doctl, and vercel to automate DNS record creation.
- [SAFE]: The skill explicitly mandates that the agent must never ask for, handle, or echo credentials or tokens, ensuring that sensitive authentication data remains within the local environment's existing security context.
- [SAFE]: Robust operational safety rules are implemented, requiring the agent to show exact commands and obtain explicit user consent before performing any visible infrastructure changes.
- [SAFE]: The skill focuses on well-known cloud services for their intended administrative purposes, aligning with the vendor's primary functionality.
- [PROMPT_INJECTION]: While the skill interacts with external infrastructure data which could theoretically serve as a vector for indirect prompt injection, the risk is mitigated by the requirement for human-in-the-loop verification for all executed commands.
Audit Metadata