convex-optimize
get-convex/agent-skills
Audit and optimize Convex apps with security, scale, and observability improvements.
What is convex-optimize?
Audits an existing Convex application using launch-readiness scoring, then applies prioritized fixes for security, upgrades, and observability. Use this to systematically improve a deployed Convex app before or after going to production.
- Detects Convex app structure and deployment type (anonymous or cloud)
- Runs scored assessment via launch-readiness to identify security, data-loss, and scale risks
- Checks for stale @convex-dev/* dependencies and suggests upgrades
- Flags observability gaps and offers to install sentinel for error capture
- Presents a prioritized fix plan ordered by security and data-loss impact
- Re-assesses after applying changes to show improvement in launch-readiness score
How to install convex-optimize
npx skills add https://github.com/get-convex/agent-skills --skill convex-optimize- An existing Convex app with a convex/ directory
- Convex CLI installed and authenticated
- Access to the app's source code and schema
How to use convex-optimize
- 1.Run the skill to detect your Convex app and trigger the launch-readiness assessment
- 2.Review the scored report and prioritized fix plan presented by the skill
- 3.Confirm the plan before any changes are applied to your codebase
- 4.The skill dispatches each fix to its corresponding capability (upgrades, observability, etc.)
- 5.After fixes are applied, the skill re-runs launch-readiness and shows the score improvement
Use cases
- Prepare an existing Convex app for production by addressing security and observability gaps
- Upgrade stale Convex dependencies as part of a maintenance cycle
- Identify and fix authorization or data-loss risks before scaling
- Add production error monitoring to an app missing observability
- Audit a Convex codebase to understand readiness and prioritize remediation work
- Convex app developers and maintainers
- DevOps or platform engineers managing Convex deployments
- Teams preparing apps for production launch
- Developers inheriting or auditing existing Convex codebases
convex-optimize FAQ
No. It presents a read-only plan first and requires explicit confirmation before making any changes.
launch-readiness is the audit/scoring engine that identifies security, data-loss, and scale issues. optimize consumes that report and acts on it by applying upgrades, installing observability, and re-assessing afterward.
It will check for stale @convex-dev/* components and include them in the prioritized plan, but only applies them after you confirm.
The skill flags the gap and offers to install sentinel for production error capture as part of the fix plan.
Yes, but it is designed to be safe: it presents a plan first, requires confirmation, and re-assesses after changes to show the impact.
Full instructions (SKILL.md)
Source of truth, from get-convex/agent-skills.
name: convex-optimize description: "Audit and optimize an existing Convex app: security, scale, upgrades, observability."
<!-- GENERATED from convex-agents content/capabilities/optimize.json — do not edit by hand. -->Audit and optimize an existing Convex app
The remediation WORKFLOW for an existing app: open with a scored assessment, then act on it — upgrade stale components and set up observability — plan-then-confirm-then-apply. The assessment itself is delegated to launch-readiness (the findings-bus scorer); optimize's distinct value is the actions it takes on the result.
Workflow
- Detect the app: a
convex/directory, the schema, and whether it's an anonymous or cloud deployment. - ASSESS via
launch-readiness— one scored, deduped report across authz/reviewer/advisor/insights with an ordered fix plan. Do not re-run those passes by hand; optimize consumes launch-readiness's report rather than re-implementing the audit. - UPGRADE: run
check-updatesagainst the pinned@convex-dev/*components and fold stale-component (staleness-class) findings into the same plan. - OBSERVABILITY: if the readiness report flagged an observability gap (no prod error capture), offer to install
sentinel. - Present the combined prioritized plan — the launch-readiness score + the fix plan + upgrades + observability, security/data-loss first — and apply only on explicit confirmation, dispatching each fix to its fixCapability.
- After applying, re-run the launch-readiness assessment and show the score delta.
Rules
- Read-only first. Present a plan and CONFIRM before changing any file.
- Delegate the audit to launch-readiness (the findings-bus scorer); don't re-implement reviewer/advisor/insights inline — optimize's job is acting on the report (upgrades + observability), not re-scoring.
- Prioritize security and data-loss risks above style, following launch-readiness's ordering.
- Never auto-land changes on someone's existing prod app; re-assess after applying and show the score moved.
Related skills
More from get-convex/agent-skills and the wider catalog.

convex-performance-audit
Diagnose and fix Convex performance issues: reads, subscriptions, write contention, and function limits.

convex-quickstart
Scaffold a Next.js + Convex app from a one-sentence idea and run it locally in seconds.

convex-reviewer
Security, auth, and performance reviewer for Convex functions—catch anti-patterns before shipping.

convex-seed
Seed or import data into the Convex database with fixtures or bulk imports.

convex-self-heal
Production error → triaged, root-caused, repaired, certified, and proposed as a human-reviewed PR; never auto-merges.

convex-sentinel
Capture production errors in your Convex deployment with built-in redaction and optional AI-driven triage.