convex-agents
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
researchTopicworkflow example inSKILL.mddemonstrates a pattern that is susceptible to indirect prompt injection. - Ingestion points: Data is ingested from the knowledge base (the
documentstable) via theagent.searchcall inconvex/workflows.ts. - Boundary markers: The retrieved content is joined using a simple string separator (`---
`) before being interpolated into the LLM prompt, which provides weak isolation between the system instructions and the untrusted data.
- Capability inventory: The agent is configured with tools like
createTaskandsearchKnowledge, which could be targeted by instructions hidden in the knowledge base documents. - Sanitization: The provided code snippets do not include logic for sanitizing or filtering document content before it is passed to the LLM.
- [EXTERNAL_DOWNLOADS]: The skill documentation references the
@convex-dev/agentpackage and official Convex documentation domains. It also provides examples for installing theaiandopenailibraries from standard package registries.
Audit Metadata