convex-file-storage

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists of documentation and code snippets for implementing file storage in Convex applications. No malicious logic, obfuscation, or unauthorized access patterns were identified.
  • [EXTERNAL_DOWNLOADS]: The skill references resources from official Convex documentation (docs.convex.dev). These informational links originate from a well-known service and are documented neutrally.
  • [INDIRECT_PROMPT_INJECTION]: The skill outlines patterns for handling user-supplied content through file uploads and action arguments. 1. Ingestion points: SKILL.md (e.g., arguments for PDF and image generation, and file upload bodies). 2. Boundary markers: Not included in the educational code samples. 3. Capability inventory: Access to storage writes via ctx.storage.store and standard network requests. 4. Sanitization: The instructions include best practices recommending client-side validation of file types and sizes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:48 PM
Security Audit — agent-trust-hub — convex-file-storage