PluginBench
Skill
Pass
Audit score 90

convex-reviewer

get-convex/agent-skills

Security, auth, and performance reviewer for Convex functions—catch anti-patterns before shipping.

What is convex-reviewer?

Convex Code Reviewer audits functions in a convex/ directory for security vulnerabilities, authorization gaps, performance issues, and schema anti-patterns. Use it before deploying to catch critical flaws like missing auth checks, unindexed queries, and missing validators.

  • Flags missing authentication checks on public functions as Critical severity
  • Detects unindexed .filter() queries and Date.now() in query handlers as performance issues
  • Verifies all public functions have args and returns validators
  • Checks for resource ownership validation before reads and writes
  • Identifies scheduled functions incorrectly targeting api.* instead of internal.*
  • Reports findings grouped by severity with explanations and fix suggestions

How to install convex-reviewer

npx skills add https://github.com/get-convex/agent-skills --skill convex-reviewer
Claude Code
Cursor
Windsurf
Cline

How to use convex-reviewer

  1. 1.Install the skill using the provided npx command
  2. 2.Point the reviewer at your convex/ directory containing functions
  3. 3.Review the structured report grouped by severity (Critical / Important / Suggestion)
  4. 4.Address Critical findings before deployment
  5. 5.Apply Important and Suggestion fixes based on your risk tolerance

Use cases

Good for
  • Pre-deployment security audit of Convex mutation and query functions
  • Code review of authorization logic to prevent unauthorized data access
  • Performance optimization pass to eliminate full-table scans and reactivity breaks
  • Validation of function signatures and schema constraints before shipping
  • Audit of scheduled functions to ensure they use internal.* endpoints
Who it's for
  • Convex backend developers
  • Security-conscious teams shipping Convex applications
  • DevOps and code-review leads ensuring production readiness

convex-reviewer FAQ

What counts as a Critical finding?

Missing authentication checks on public mutations—any unauthenticated public function that modifies data is a data-loss risk and must be fixed before shipping.

Why does the reviewer flag .filter() on DB queries?

.filter() performs a full table scan instead of using indexes, causing performance degradation at scale. Use withIndex() to query efficiently.

What's the difference between api.* and internal.* for scheduled functions?

api.* functions are exposed to clients and should never be called by scheduled tasks. Use internal.* for server-only logic that cron jobs should invoke.

Does the reviewer check TypeScript types?

Yes—it flags any types and missing args/returns validators on public functions, which are Important issues that affect type safety and client code generation.

Can I ignore Suggestion-level findings?

Suggestions are lower-risk improvements (e.g., bounded arrays in documents). Critical and Important findings should always be addressed before production.

Full instructions (SKILL.md)

Source of truth, from get-convex/agent-skills.


name: convex-reviewer description: "Convex code reviewer — security, auth, validators, performance, and pattern checks for code in a convex/ directory. Use to review or audit Convex functions before shipping."

<!-- GENERATED from convex-agents content/capabilities/convex-reviewer.json — do not edit by hand. -->

Convex Code Reviewer

Structured review of Convex code for security, authorization, validators, performance, and schema design. Applies a Convex-specific checklist and flags anti-patterns with severity (Critical / Important / Suggestion).

Workflow

  1. First pass — Security: verify all public functions check ctx.auth.getUserIdentity(), verify resource ownership before reads/writes, confirm no client-provided user IDs are trusted, confirm scheduled functions target internal.* not api.*.
  2. Second pass — Performance: confirm no .filter() on DB queries (withIndex required), verify all foreign-key fields have indexes, confirm no Date.now() in query handlers, confirm .collect() is not used on unbounded queries.
  3. Third pass — Code quality: confirm args and returns validators on every public function, no any types, promises are awaited, arrays in documents are bounded (<8192 elements).
  4. Report findings grouped by severity; explain why each issue matters and suggest a fix.

Rules

  • Flag missing auth checks as Critical — any unauthenticated public mutation is a data-loss risk.
  • Flag .filter() on DB queries as Important — it is a full table scan.
  • Flag Date.now() in query handlers as Important — it breaks reactivity.
  • Flag missing args or returns validators as Important.
  • Flag scheduling to api.* (not internal.*) as Important.
  • Always explain why a change is needed, not just what to change.