get-convex/agent-skills

convex-reviewer

Convex code reviewer — security, auth, validators, performance, and pattern checks for code in a convex/ directory. Use to review or audit Convex functions before shipping.

All-time #998 Trending #508 Hot #5902 First seen Aug 1, 2026
8-week activity · all time api

Installation

$ npx skills add get-convex/agent-skills --skill convex-reviewer

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from get-convex/agent-skills · top by installs.

npx skills add get-convex/agent-skills

Browse all from get-convex/agent-skills

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 53
License LICENSE
Default branch main
Open issues 2
Status Active

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 1,761 B
  • docs SUMMARY.md 197 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 18,705 installs

SKILL.md

<!-- GENERATED from convex-agents content/capabilities/convex-reviewer.json — do not edit by hand. -->

Convex Code Reviewer

Structured review of Convex code for security, authorization, validators, performance, and schema design. Applies a Convex-specific checklist and flags anti-patterns with severity (Critical / Important / Suggestion).

Workflow

  1. First pass — Security: verify all public functions check ctx.auth.getUserIdentity(), verify resource ownership before reads/writes, confirm no client-provided user IDs are trusted, confirm scheduled functions target internal. not api..
  2. Second pass — Performance: confirm no .filter() on DB queries (withIndex required), verify all foreign-key fields have indexes, confirm no Date.now() in query handlers, confirm .collect() is not used on unbounded queries.
  3. Third pass — Code quality: confirm args and returns validators on every public function, no any types, promises are awaited, arrays in documents are bounded (<8192 elements).
  4. Report findings grouped by severity; explain why each issue matters and suggest a fix.

Rules

  • Flag missing auth checks as Critical — any unauthenticated public mutation is a data-loss risk.
  • Flag .filter() on DB queries as Important — it is a full table scan.
  • Flag Date.now() in query handlers as Important — it breaks reactivity.
  • Flag missing args or returns validators as Important.
  • Flag scheduling to api. (not internal.) as Important.
  • Always explain why a change is needed, not just what to change.