convex-explain-app
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted project files which may contain malicious instructions to the agent.
- Ingestion points:
schema.ts,auth.config.ts,convex.config.ts,http.ts, and theconvex/directory. - Boundary markers: None provided to distinguish between application code and agent instructions.
- Capability inventory: Read-only source analysis and summarization; no write or network permissions identified within the skill's instructions.
- Sanitization: No explicit filtering or validation of the ingested source code content is performed.
Audit Metadata