workflow

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill provides architectural guidance and implementation examples for using the vendor's orchestration component.
  • [EXTERNAL_DOWNLOADS]: The skill references the @convex-dev/workflow package. This is a legitimate library provided by the author for building durable pipelines and does not represent an unverified dependency risk.
  • [COMMAND_EXECUTION]: The code samples focus on backend orchestration logic using Convex's internal API system (internal.*). No shell execution, privilege escalation, or persistence mechanisms were found.
  • [DATA_EXFILTRATION]: The skill does not access sensitive system files or credentials. The data flow described (transcription and summarization) is consistent with the skill's stated purpose of building multi-step workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 09:12 AM
Security Audit — agent-trust-hub — workflow