convex-development-general

Fail

Audited by Snyk on May 10, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (high risk: 1.00). The prompt includes a "Memory Protocol" that mandatorily instructs reading a local .claude/context/memory file and recording memories—an out-of-scope, potentially data-exfiltration directive unrelated to Convex development, so it is a hidden/deceptive instruction.

Issues (1)

E004
CRITICAL

Prompt injection detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
May 10, 2026, 07:26 PM
Issues
1
Security Audit — snyk — convex-development-general