convex-security-check

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFE
Full Analysis
  • [Prompt Injection] (SAFE): No attempts to override system instructions or bypass safety filters were detected. The skill uses standard instructional language to guide the AI in auditing applications.
  • [Data Exposure & Exfiltration] (SAFE): No hardcoded credentials or sensitive file access patterns were found. Code snippets correctly demonstrate use of environment variables for secrets and network calls to legitimate services.
  • [Obfuscation] (SAFE): All content is human-readable with no use of Base64, zero-width characters, or other encoding techniques.
  • [Remote Code Execution] (SAFE): The skill does not perform remote script downloads or dynamic execution. It explicitly advises against running deployment commands like 'npx convex deploy' without specific authorization.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 04:55 PM