convex-suggest

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to provide passive suggestions for Convex components and includes explicit instructions never to perform installations without user consent.- [EXTERNAL_DOWNLOADS]: The skill references several official Convex-owned packages including @convex-dev/crons, @convex-dev/sharded-counter, @convex-dev/aggregate, @convex-dev/workflow, @convex-dev/workpool, @convex-dev/rate-limiter, @convex-dev/presence, @convex-dev/rag, and @convex-dev/prosemirror-sync. These are verified vendor resources.- [INDIRECT_PROMPT_INJECTION]: While the skill ingests untrusted code snippets and user input to trigger suggestions, the potential impact is limited by a predefined list of components and the requirement for human-in-the-loop confirmation before the /add command is executed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 03:14 PM
Security Audit — agent-trust-hub — convex-suggest