suggest
Pass
Audited by Gen Agent Trust Hub on Aug 31, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes user-provided code and intent to suggest relevant Convex components, which constitutes a standard ingestion of untrusted data.
- Ingestion points: The skill monitors
codeSnippetsanduserAskfrom the user context. - Boundary markers: No specific delimiters or boundary instructions are defined in the skill for isolating user code.
- Capability inventory: The skill is authorized to surface suggestions and invoke the
/addcommand for component installation only after receiving explicit user confirmation. - Sanitization: No explicit sanitization or filtering of the ingested code snippets is described; the skill relies on pattern matching for component detection.
Audit Metadata