convex-reviewer

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional text defining a code review process for Convex applications. It does not download external scripts, execute arbitrary commands, or access sensitive credentials.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze code in a convex/ directory, which serves as an ingestion point for untrusted data. However, the instructions do not involve high-risk capabilities like network access or file system modifications based on the processed content, resulting in a safe assessment.
  • Ingestion points: Code files in the convex/ directory as described in the workflow.
  • Boundary markers: None specified in the instructions.
  • Capability inventory: The skill does not define or request specific tool access for network operations, file writing, or command execution.
  • Sanitization: No specific filtering or escaping mechanisms are described.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 03:14 PM
Security Audit — agent-trust-hub — convex-reviewer