convex-launch-readiness
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a high-level orchestrator that composes existing audit capabilities (convex-authz, convex-reviewer, etc.). It does not implement new logic that would bypass security boundaries.
- [SAFE]: Data ingestion and reporting utilize structured schemas (finding.schema.json), which significantly mitigates the risk of indirect prompt injection by ensuring inputs are validated against expected formats.
- [SAFE]: The skill adheres to a read-only aggregation model for its primary function. While it can dispatch to 'fixer' capabilities, these actions are explicitly gated by user consent and deployment target rules.
- [SAFE]: No evidence of obfuscation, unauthorized network communication, or sensitive credential harvesting was detected. All referenced tools and resources are within the 'get-convex' vendor context.
Audit Metadata