convex-reviewer
get-convex/agent-skills
Security, auth, and performance reviewer for Convex functions—catch anti-patterns before shipping.
What is convex-reviewer?
Convex Code Reviewer audits functions in a convex/ directory for security vulnerabilities, authorization gaps, performance issues, and schema anti-patterns. Use it before deploying to catch critical flaws like missing auth checks, unindexed queries, and missing validators.
- Flags missing authentication checks on public functions as Critical severity
- Detects unindexed .filter() queries and Date.now() in query handlers as performance issues
- Verifies all public functions have args and returns validators
- Checks for resource ownership validation before reads and writes
- Identifies scheduled functions incorrectly targeting api.* instead of internal.*
- Reports findings grouped by severity with explanations and fix suggestions
How to install convex-reviewer
npx skills add https://github.com/get-convex/agent-skills --skill convex-reviewerHow to use convex-reviewer
- 1.Install the skill using the provided npx command
- 2.Point the reviewer at your convex/ directory containing functions
- 3.Review the structured report grouped by severity (Critical / Important / Suggestion)
- 4.Address Critical findings before deployment
- 5.Apply Important and Suggestion fixes based on your risk tolerance
Use cases
- Pre-deployment security audit of Convex mutation and query functions
- Code review of authorization logic to prevent unauthorized data access
- Performance optimization pass to eliminate full-table scans and reactivity breaks
- Validation of function signatures and schema constraints before shipping
- Audit of scheduled functions to ensure they use internal.* endpoints
- Convex backend developers
- Security-conscious teams shipping Convex applications
- DevOps and code-review leads ensuring production readiness
convex-reviewer FAQ
Missing authentication checks on public mutations—any unauthenticated public function that modifies data is a data-loss risk and must be fixed before shipping.
.filter() performs a full table scan instead of using indexes, causing performance degradation at scale. Use withIndex() to query efficiently.
api.* functions are exposed to clients and should never be called by scheduled tasks. Use internal.* for server-only logic that cron jobs should invoke.
Yes—it flags any types and missing args/returns validators on public functions, which are Important issues that affect type safety and client code generation.
Suggestions are lower-risk improvements (e.g., bounded arrays in documents). Critical and Important findings should always be addressed before production.
Full instructions (SKILL.md)
Source of truth, from get-convex/agent-skills.
name: convex-reviewer description: "Convex code reviewer — security, auth, validators, performance, and pattern checks for code in a convex/ directory. Use to review or audit Convex functions before shipping."
<!-- GENERATED from convex-agents content/capabilities/convex-reviewer.json — do not edit by hand. -->Convex Code Reviewer
Structured review of Convex code for security, authorization, validators, performance, and schema design. Applies a Convex-specific checklist and flags anti-patterns with severity (Critical / Important / Suggestion).
Workflow
- First pass — Security: verify all public functions check ctx.auth.getUserIdentity(), verify resource ownership before reads/writes, confirm no client-provided user IDs are trusted, confirm scheduled functions target internal.* not api.*.
- Second pass — Performance: confirm no .filter() on DB queries (withIndex required), verify all foreign-key fields have indexes, confirm no Date.now() in query handlers, confirm .collect() is not used on unbounded queries.
- Third pass — Code quality: confirm args and returns validators on every public function, no any types, promises are awaited, arrays in documents are bounded (<8192 elements).
- Report findings grouped by severity; explain why each issue matters and suggest a fix.
Rules
- Flag missing auth checks as Critical — any unauthenticated public mutation is a data-loss risk.
- Flag .filter() on DB queries as Important — it is a full table scan.
- Flag Date.now() in query handlers as Important — it breaks reactivity.
- Flag missing args or returns validators as Important.
- Flag scheduling to api.* (not internal.*) as Important.
- Always explain why a change is needed, not just what to change.
Related skills
More from get-convex/agent-skills and the wider catalog.

convex-seed
Seed or import data into the Convex database with fixtures or bulk imports.

convex-self-heal
Production error → triaged, root-caused, repaired, certified, and proposed as a human-reviewed PR; never auto-merges.

convex-sentinel
Capture production errors in your Convex deployment with built-in redaction and optional AI-driven triage.

convex-setup-auth
Set up secure authentication in Convex with user management and access control.

convex-suggest
Suggest the right Convex component when you detect hand-rolled patterns it already solves.

convex-test
Generate convex-test tests for Convex functions using vitest and an in-memory backend.