convex-domains

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to utilize existing authenticated command-line interfaces such as flarectl, aws, gcloud, doctl, and vercel to automate DNS record creation.
  • [SAFE]: The skill explicitly mandates that the agent must never ask for, handle, or echo credentials or tokens, ensuring that sensitive authentication data remains within the local environment's existing security context.
  • [SAFE]: Robust operational safety rules are implemented, requiring the agent to show exact commands and obtain explicit user consent before performing any visible infrastructure changes.
  • [SAFE]: The skill focuses on well-known cloud services for their intended administrative purposes, aligning with the vendor's primary functionality.
  • [PROMPT_INJECTION]: While the skill interacts with external infrastructure data which could theoretically serve as a vector for indirect prompt injection, the risk is mitigated by the requirement for human-in-the-loop verification for all executed commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 05:25 PM
Security Audit — agent-trust-hub — convex-domains