local-convex

Warn

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONPRIVILEGE_ESCALATIONPERSISTENCEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill provides a hardcoded password 'minioadminPassWD9001' for a reference service instance.
  • [COMMAND_EXECUTION]: Instructs the agent to perform high-impact system operations including 'sudo', 'ssh', and 'tailscale serve' for infrastructure and network management.
  • [PRIVILEGE_ESCALATION]: Extensive reliance on 'sudo' for administrative tasks such as Postgres management, NAS installer execution, and system service installation.
  • [PERSISTENCE]: Includes instructions for setting up a macOS LaunchDaemon ('com.joelclaw.local-convex.lan-forwarder.plist.template') to ensure local network forwarders persist across system reboots.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local configuration files and documentation, which could potentially contain malicious instructions. 1. Ingestion points: Reads configuration from 'convex-s3.env' and project notes in '/Users/joel/.brain/'. 2. Boundary markers: None identified. 3. Capability inventory: Significant access including 'sudo', 'ssh', and network forwarding management. 4. Sanitization: No sanitization or validation of external file content is described.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 23, 2026, 05:03 PM
Security Audit — agent-trust-hub — local-convex