convex-advisor
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from production deployment insights, including function logs and metadata, which are external and potentially attacker-influenced sources.
- Ingestion points:
insightstool andlogsoutput processed inSKILL.md(Step 2 and 3). - Boundary markers: No specific delimiters or safety warnings for embedded content are defined in the instructions.
- Capability inventory: The skill reads application source code, performs analysis, and emits findings to a structured findings bus (
specs/finding.schema.json). - Sanitization: No explicit sanitization or filtering of the ingested log content is mentioned before processing.
Audit Metadata