Skip to main content
ZICQ

Skills ZICQ category:Security convex-reviewer

Convex Reviewer

Convex code reviewer — security, auth, validators, performance, and pattern checks for code in a convex/ directory. Use to review or audit Convex functions before shipping.

20324 installs

Official URL:skills.sh

What this skill does

Intro in this page language first. The official description stays in its original wording; we do not rewrite SKILL.md.

What it does

Convex code reviewer — security, auth, validators, performance, and pattern checks for code in a convex/ directory. Use to review or audit Convex functions before shipping.

When to use it

The official description does not include a separate “Use when”. Per the spec, agents activate this skill when the task matches keywords in that description.

How agents load it

Per Agent Skills progressive disclosure: name and description load at startup (~100 tokens); the full SKILL.md body loads when the skill activates; scripts/, references/, and assets/ load only as needed. This file's sections: Convex Code Reviewer; Workflow; Rules. It includes spec-recommended sections: step-by-step instructions.

File analysis

File analysis: instruction-only skill (SKILL.md). The agent loads the full body when activated.

Convex Code ReviewerWorkflowRules

Source category:skills.sh agent-skill

SKILL.md & Agent activation

Official spec ↗
name
convex-reviewer
description
Convex code reviewer — security, auth, validators, performance, and pattern checks for code in a convex/ directory. Use to review or audit Convex functions before shipping.
  1. DiscoverThe client exposes names and descriptions to the agent.
  2. ActivateYour request or the task context selects the skill and loads its instructions.
  3. Load resourcesReferenced scripts, documentation and assets are used when needed.

Invocation syntax and available tools depend on your Agent client. Client integration guide ↗

Install this skill

Skills CLI ↗

Choose the target agent and installation scope, keep referenced package files, then verify the skill appears in the client's catalog.

Ask your Agent to install

Copy these instructions to a compatible agent and confirm the target directory matches your client.

Install the agent skill "convex-reviewer" into my project. The full SKILL.md and official description are at https://zicq.com/en/skills/skl-aaa821b96e8de68a-Convex-Reviewer.html
Save it as .cursor/skills/convex-reviewer/SKILL.md or .claude/skills/convex-reviewer/SKILL.md and keep the frontmatter name and description exactly as-is.

Full package on GitHub ↗

Install from the terminal · Skills CLI

Requires Node.js and npx. First inspect the repository's skill list to confirm the name.

npx skills add 'https://github.com/get-convex/agent-skills' --list

npx skills add 'https://github.com/get-convex/agent-skills' --skill 'convex-reviewer'

The CLI lets you choose the agent interactively. The default scope is the project; use -g for user scope. Confirm package availability with the discovery command, then use npx skills list to inspect installed skills.

Readable layout
--- name: convex-reviewer description: "Convex code reviewer — security, auth, validators, performance, and pattern checks for code in a convex/ directory. Use to review or audit Convex functions before shipping." --- # Convex Code Reviewer Structured review of Convex code for security, authorization, validators, performance, and schema design. Applies a Convex-specific checklist and flags anti-patterns with severity (Critical / Important / Suggestion). ## Workflow 1. First pass — Security: verify all public functions check ctx.auth.getUserIdentity(), verify resource ownership before reads/writes, confirm no client-provided user IDs are trusted, confirm scheduled functions target internal.* not api.*. 2. Second pass — Performance: confirm no .filter() on DB queries (withIndex required), verify all foreign-key fields have indexes, confirm no Date.now() in query handlers, confirm .collect() is not used on unbounded queries. 3. Third pass — Code quality: confirm args and returns validators on every public function, no any types, promises are awaited, arrays in documents are bounded (<8192 elements). 4. Report findings grouped by severity; explain why each issue matters and suggest a fix. ## Rules - Flag missing auth checks as Critical — any unauthenticated public mutation is a data-loss risk. - Flag .filter() on DB queries as Important — it is a full table scan. - Flag Date.now() in query handlers as Important — it breaks reactivity. - Flag missing args or returns validators as Important. - Flag scheduling to api.* (not internal.*) as Important. - Always explain why a change is needed, not just what to change.

Related skills

Security

Skill Vetter

Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, p…

Security

Moltguard

MoltGuard — OpenClaw security guard by OpenGuardrails. Install MoltGuard to protect you and your human from prompt injection, data exfiltrat…

Security

Security Auditor

Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers…

Security

Skill Vetter

Security vetting protocol before installing any AI agent skill. Red flag detection for credential theft, obfuscated code, exfiltration. Risk…