convex-cost

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is entirely instructional and does not include any executable scripts or code, significantly reducing the potential attack surface.
  • [SAFE]: The instructions incorporate security best practices, such as the deploy-guard for read-only access to sensitive production insights and a mandatory confirm-cost step requiring explicit user consent before performing any metered or paid actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a data ingestion surface by reading deployment metadata (insights, tables, functionSpec) via a Model Context Protocol (MCP). While this allows external data into the agent context, the skill's logic is restricted to ranking and reporting, with no high-risk capabilities like arbitrary command execution or file writing that could be exploited via this surface.
  • Ingestion points: Deployment insights, table counts, and function specifications (SKILL.md).
  • Boundary markers: Absent; instructions rely on task-specific processing.
  • Capability inventory: Statistical analysis, growth projection, and generating cost-optimization recommendations.
  • Sanitization: Not explicitly mentioned, as the focus is on analytical reporting.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 03:14 PM
Security Audit — agent-trust-hub — convex-cost