workflow
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill provides architectural guidance and implementation examples for using the vendor's orchestration component.
- [EXTERNAL_DOWNLOADS]: The skill references the
@convex-dev/workflowpackage. This is a legitimate library provided by the author for building durable pipelines and does not represent an unverified dependency risk. - [COMMAND_EXECUTION]: The code samples focus on backend orchestration logic using Convex's internal API system (
internal.*). No shell execution, privilege escalation, or persistence mechanisms were found. - [DATA_EXFILTRATION]: The skill does not access sensitive system files or credentials. The data flow described (transcription and summarization) is consistent with the skill's stated purpose of building multi-step workflows.
Audit Metadata