convex-insights
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a structured workflow for observability using official Convex MCP tools (logs, insights, status). It explicitly enforces a read-only policy by instructing the agent never to enable production mutation flags during health checks.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data from application logs and insights, which represents an indirect prompt injection surface. The risk is mitigated by the skill's architecture, which requires the agent to filter data client-side and provide aggregated evidence (counts and stacks) rather than echoing raw, potentially malicious log content directly back to the user or downstream processes.
Audit Metadata