convex-realtime

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical reference for the Convex Realtime platform. All provided code samples and instructions align with standard React and Convex development practices.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns were detected. The skill includes explicit security best practices that advise the agent not to run deployment (npx convex deploy) or git commands unless specifically instructed.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for ingesting data from an external database (Convex). While this technically establishes a surface for indirect prompt injection via stored data, the skill itself is purely instructional and does not provide access to dangerous capabilities or sensitive system tools that could be abused through such an injection.
  • [DATA_EXFILTRATION]: No data exfiltration vectors were identified. All network references target the official Convex documentation domains (convex.dev), which are legitimate resources for the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:47 PM
Security Audit — agent-trust-hub — convex-realtime