convex-suggest

Pass

Audited by Gen Agent Trust Hub on Aug 1, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [NO_CODE]: The skill consists exclusively of instructional markdown and does not include any executable scripts or binary files, minimizing the direct execution risk.- [PROMPT_INJECTION]: The skill defines a surface for processing untrusted data from user code and queries. This is assessed as safe based on the following: 1. Ingestion points: user code snippets and asks matched against detector rules. 2. Boundary markers: Not specified in the instructions. 3. Capability inventory: Limited to suggesting the '/add' tool, which requires explicit human consent. 4. Sanitization: Relies on user review and platform-level safety filters.- [SAFE]: All referenced dependencies and tools belong to the official '@convex-dev' scope, which is consistent with the skill's authoring organization. The skill explicitly forbids installation without consent and ignores suggestions if the user declines.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 1, 2026, 05:25 PM
Security Audit — agent-trust-hub — convex-suggest