convex-advisor

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from production deployment insights, including function logs and metadata, which are external and potentially attacker-influenced sources.
  • Ingestion points: insights tool and logs output processed in SKILL.md (Step 2 and 3).
  • Boundary markers: No specific delimiters or safety warnings for embedded content are defined in the instructions.
  • Capability inventory: The skill reads application source code, performs analysis, and emits findings to a structured findings bus (specs/finding.schema.json).
  • Sanitization: No explicit sanitization or filtering of the ingested log content is mentioned before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 03:14 PM
Security Audit — agent-trust-hub — convex-advisor