convex-insights

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a structured workflow for observability using official Convex MCP tools (logs, insights, status). It explicitly enforces a read-only policy by instructing the agent never to enable production mutation flags during health checks.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from application logs and insights, which represents an indirect prompt injection surface. The risk is mitigated by the skill's architecture, which requires the agent to filter data client-side and provide aggregated evidence (counts and stacks) rather than echoing raw, potentially malicious log content directly back to the user or downstream processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 05:25 PM
Security Audit — agent-trust-hub — convex-insights