convex-self-heal

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes production error data and triggering inputs, representing a potential surface for indirect prompt injection.\n
  • Ingestion points: Production error logs from the sentinel table and replayed triggering inputs.\n
  • Boundary markers: Errors are explicitly stated to be redacted at write time.\n
  • Capability inventory: Branch creation, PR proposal, TypeScript compilation (tsc), and MCP-based queries.\n
  • Sanitization: Mitigated by triage classification, redaction, and mandatory human review.\n- [COMMAND_EXECUTION]: Development tools like tsc and platform utilities like migrate-rehearse are used for verification in isolated preview environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 03:15 PM
Security Audit — agent-trust-hub — convex-self-heal