convex-suggest
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: The skill consists exclusively of instructional markdown and does not include any executable scripts or binary files, minimizing the direct execution risk.- [PROMPT_INJECTION]: The skill defines a surface for processing untrusted data from user code and queries. This is assessed as safe based on the following: 1. Ingestion points: user code snippets and asks matched against detector rules. 2. Boundary markers: Not specified in the instructions. 3. Capability inventory: Limited to suggesting the '/add' tool, which requires explicit human consent. 4. Sanitization: Relies on user review and platform-level safety filters.- [SAFE]: All referenced dependencies and tools belong to the official '@convex-dev' scope, which is consistent with the skill's authoring organization. The skill explicitly forbids installation without consent and ignores suggestions if the user declines.
Audit Metadata