convex-self-heal
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes production error data and triggering inputs, representing a potential surface for indirect prompt injection.\n
- Ingestion points: Production error logs from the sentinel table and replayed triggering inputs.\n
- Boundary markers: Errors are explicitly stated to be redacted at write time.\n
- Capability inventory: Branch creation, PR proposal, TypeScript compilation (tsc), and MCP-based queries.\n
- Sanitization: Mitigated by triage classification, redaction, and mandatory human review.\n- [COMMAND_EXECUTION]: Development tools like tsc and platform utilities like migrate-rehearse are used for verification in isolated preview environments.
Audit Metadata