convex-agents

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The researchTopic workflow example in SKILL.md demonstrates a pattern that is susceptible to indirect prompt injection.
  • Ingestion points: Data is ingested from the knowledge base (the documents table) via the agent.search call in convex/workflows.ts.
  • Boundary markers: The retrieved content is joined using a simple string separator (`---

`) before being interpolated into the LLM prompt, which provides weak isolation between the system instructions and the untrusted data.

  • Capability inventory: The agent is configured with tools like createTask and searchKnowledge, which could be targeted by instructions hidden in the knowledge base documents.
  • Sanitization: The provided code snippets do not include logic for sanitizing or filtering document content before it is passed to the LLM.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references the @convex-dev/agent package and official Convex documentation domains. It also provides examples for installing the ai and openai libraries from standard package registries.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:01 PM
Security Audit — agent-trust-hub — convex-agents