convex-optimize
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: A vulnerability surface for indirect prompt injection was identified. The skill processes untrusted application code from the 'convex/' directory and possesses capabilities to modify files and install packages. While the workflow includes a confirmation step, malicious instructions embedded in the audited code could potentially influence the audit score or the contents of the proposed fix plan. 1. Ingestion points: Application source code and schema files in the 'convex/' directory. 2. Boundary markers: Absent. 3. Capability inventory: File-writing for applying fixes, component updates via 'check-updates', and installation of the 'sentinel' tool. 4. Sanitization: Not specified for the ingestion of existing application data.\n- [EXTERNAL_DOWNLOADS]: The skill manages updates for '@convex-dev/*' packages and offers to install the 'sentinel' observability tool. These resources appear to be legitimate components of the vendor's application maintenance ecosystem.
Audit Metadata