convex-explain-app
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from the user's project files. * Ingestion points: The agent is instructed to read schema.ts, auth.config.ts, convex.config.ts, http.ts, and function source code from the convex/ directory. * Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' prompts when processing the content of these files. * Capability inventory: The skill uses read-only tools to introspect the file system and deployment metadata. No destructive or exfiltration capabilities are identified. * Sanitization: There is no evidence of filtering or sanitization of the content read from the source files before it is processed by the agent.
Audit Metadata