convex-security-audit

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive security audit patterns for authorization logic, data access boundaries, and sensitive operations. The code snippets follow defensive programming standards.
  • [EXTERNAL_DOWNLOADS]: Fetches documentation and broader context from official Convex domains (docs.convex.dev), which are well-known services for application developers.
  • [CREDENTIALS_UNSAFE]: The skill demonstrates proper security hygiene by using environment variables (process.env.EXTERNAL_API_KEY, process.env.STRIPE_SECRET_KEY) to handle secrets rather than hardcoding them in scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill outlines patterns for handling external data from a database (ctx.db.query in convex/data.ts). It addresses potential injection risks through a clear evidence chain:
  • Ingestion points: Data is queried from the userData, sensitiveItems, and documents tables in convex/data.ts.
  • Boundary markers: Explicit ownership checks (item.ownerId !== user._id) and role-based access requirements (requireRole, requirePermission) are implemented throughout the logic.
  • Capability inventory: Uses ctx.db.insert, ctx.db.delete, and fetch to interact with external APIs.
  • Sanitization: Examples include explicit response sanitization (sanitizeResponse(data)) before returning data to the caller.
  • [METADATA_POISONING]: There is a discrepancy between the author 'Convex' listed in the YAML frontmatter and the platform-provided author 'waynesutton'. However, the content is consistent with a security audit template for the Convex platform and does not show deceptive intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:01 PM
Security Audit — agent-trust-hub — convex-security-audit