convex-optimize

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: A vulnerability surface for indirect prompt injection was identified. The skill processes untrusted application code from the 'convex/' directory and possesses capabilities to modify files and install packages. While the workflow includes a confirmation step, malicious instructions embedded in the audited code could potentially influence the audit score or the contents of the proposed fix plan. 1. Ingestion points: Application source code and schema files in the 'convex/' directory. 2. Boundary markers: Absent. 3. Capability inventory: File-writing for applying fixes, component updates via 'check-updates', and installation of the 'sentinel' tool. 4. Sanitization: Not specified for the ingestion of existing application data.\n- [EXTERNAL_DOWNLOADS]: The skill manages updates for '@convex-dev/*' packages and offers to install the 'sentinel' observability tool. These resources appear to be legitimate components of the vendor's application maintenance ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 03:15 PM
Security Audit — agent-trust-hub — convex-optimize