LabscoConnect MCP ↗
get-convex logo✓ Official★ 63

convex-reviewer

Reviews the code in a Convex app's convex folder before you ship, in three passes: security, performance and code quality. Each finding is marked Critical, Important or Suggestion, with why it matters and how to fix it.

by get-convexpart of get-convex/agent-skills

One of 30 skills in the get-convex/agent-skills package — works on its own, and pairs well with its siblings.

WHEN YOUR AGENT SHOULD USE IT

A QUICK BOUNDARY

USE FOR

  • Catch public functions that skip the sign-in check.
  • Spot full-table scans and missing indexes.
  • Find query code that stops live updates, such as reading the current time.
  • Check every function checks its inputs and outputs.

Documents

This is the playbook your agent receives when the skill activates — you don't need to read it to use the skill, but it's here to audit before installing.

Convex Code Reviewer

Structured review of Convex code for security, authorization, validators, performance, and schema design. Applies a Convex-specific checklist and flags anti-patterns with severity (Critical / Important / Suggestion).

Workflow
  1. First pass — Security: verify all public functions check ctx.auth.getUserIdentity(), verify resource ownership before reads/writes, confirm no client-provided user IDs are trusted, confirm scheduled functions target internal.* not api.*.
  2. Second pass — Performance: confirm no .filter() on DB queries (withIndex required), verify all foreign-key fields have indexes, confirm no Date.now() in query handlers, confirm .collect() is not used on unbounded queries.
  3. Third pass — Code quality: confirm args and returns validators on every public function, no any types, promises are awaited, arrays in documents are bounded (<8192 elements).
  4. Report findings grouped by severity; explain why each issue matters and suggest a fix.
Rules
  • Flag missing auth checks as Critical — any unauthenticated public mutation is a data-loss risk.
  • Flag .filter() on DB queries as Important — it is a full table scan.
  • Flag Date.now() in query handlers as Important — it breaks reactivity.
  • Flag missing args or returns validators as Important.
  • Flag scheduling to api.* (not internal.*) as Important.
  • Always explain why a change is needed, not just what to change.

Installation

Copy & paste — that's it
npx skills add get-convex/agent-skills --skill "convex-reviewer" --full-depth

Run this in your project — your agent picks the skill up automatically.

License

Licensed under Apache-2.0— you can use, modify, and redistribute it under that license's terms.

View the full license file on GitHub →