convex-security-audit
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides comprehensive security audit patterns for authorization logic, data access boundaries, and sensitive operations. The code snippets follow defensive programming standards.
- [EXTERNAL_DOWNLOADS]: Fetches documentation and broader context from official Convex domains (
docs.convex.dev), which are well-known services for application developers. - [CREDENTIALS_UNSAFE]: The skill demonstrates proper security hygiene by using environment variables (
process.env.EXTERNAL_API_KEY,process.env.STRIPE_SECRET_KEY) to handle secrets rather than hardcoding them in scripts. - [INDIRECT_PROMPT_INJECTION]: The skill outlines patterns for handling external data from a database (
ctx.db.queryinconvex/data.ts). It addresses potential injection risks through a clear evidence chain: - Ingestion points: Data is queried from the
userData,sensitiveItems, anddocumentstables inconvex/data.ts. - Boundary markers: Explicit ownership checks (
item.ownerId !== user._id) and role-based access requirements (requireRole,requirePermission) are implemented throughout the logic. - Capability inventory: Uses
ctx.db.insert,ctx.db.delete, andfetchto interact with external APIs. - Sanitization: Examples include explicit response sanitization (
sanitizeResponse(data)) before returning data to the caller. - [METADATA_POISONING]: There is a discrepancy between the author 'Convex' listed in the YAML frontmatter and the platform-provided author 'waynesutton'. However, the content is consistent with a security audit template for the Convex platform and does not show deceptive intent.
Audit Metadata