convex-deploy-guard

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard Convex CLI commands such as npx convex deploy, npx convex run, and npx convex env list. These are identified as legitimate developer tools associated with the vendor's platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest local configuration data from files like .env.local and convex.json to identify deployment targets.
  • Ingestion points: Reads project configuration from .env.local and convex.json (SKILL.md).
  • Boundary markers: None explicitly defined for file reading, but the skill mandates a human-in-the-loop confirmation step ('ANNOUNCE in one line before any deployment-affecting command') which serves as a safety boundary.
  • Capability inventory: Uses the Convex CLI (npx convex) to perform deployments and environment management.
  • Sanitization: Relies on the user to verify the 'announced' target before execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 03:14 PM
Security Audit — agent-trust-hub — convex-deploy-guard