convex-reviewer

作成者: get-convex

Convexコードレビュアー — convex/ ディレクトリ内のコードに対するセキュリティ、認証、バリデーター、パフォーマンス、パターンチェック。リリース前にConvex関数をレビューまたは監査するために使用します。

npx skills add https://github.com/get-convex/agent-skills --skill convex-reviewer

Convex Code Reviewer

Structured review of Convex code for security, authorization, validators, performance, and schema design. Applies a Convex-specific checklist and flags anti-patterns with severity (Critical / Important / Suggestion).

Workflow

  1. First pass — Security: verify all public functions check ctx.auth.getUserIdentity(), verify resource ownership before reads/writes, confirm no client-provided user IDs are trusted, confirm scheduled functions target internal.* not api.*.
  2. Second pass — Performance: confirm no .filter() on DB queries (withIndex required), verify all foreign-key fields have indexes, confirm no Date.now() in query handlers, confirm .collect() is not used on unbounded queries.
  3. Third pass — Code quality: confirm args and returns validators on every public function, no any types, promises are awaited, arrays in documents are bounded (<8192 elements).
  4. Report findings grouped by severity; explain why each issue matters and suggest a fix.

Rules

  • Flag missing auth checks as Critical — any unauthenticated public mutation is a data-loss risk.
  • Flag .filter() on DB queries as Important — it is a full table scan.
  • Flag Date.now() in query handlers as Important — it breaks reactivity.
  • Flag missing args or returns validators as Important.
  • Flag scheduling to api.* (not internal.*) as Important.
  • Always explain why a change is needed, not just what to change.

get-convexのその他のスキル

convex-performance-audit
get-convex
Convexのパフォーマンスを、読み取り、サブスクリプション、書き込み競合、関数制限について監査します。遅い機能、インサイトの調査結果、OCC競合、または読み取り増幅に使用します。
developmentdatabasedata-analysis
convex
get-convex
一般的なConvexリクエストを適切なプロジェクトスキルにルーティングします。ユーザーがどのConvexスキルを使用すべきか尋ねたり、不十分に指定されたConvexアプリタスクを与えた場合に使用します。
developmentdatabase
convex-setup-auth
get-convex
Convexの認証、IDマッピング、アクセス制御を設定します。Convexアプリでのログイン、認証プロバイダー、ユーザーテーブル、保護された関数、ロールに使用します。
developmentdatabaseapi
convex-quickstart
get-convex
アプリにConvexを作成または追加します。新しいConvexプロジェクト、npm create convex@latest、フロントエンドのセットアップ、環境変数、または最初のnpx convex devの実行に使用します。
developmentdatabase
convex-migration-helper
get-convex
Convexのスキーマとデータマイグレーションを、widen-migrate-narrowおよび@convex-dev/migrationsを用いて計画します。破壊的なスキーマ変更、バックフィル、テーブル再構築、またはダウンタイムゼロのロールアウトに使用します。
developmentdatabase
convex-create-component
get-convex
再利用可能なConvexコンポーネントを、独立したテーブルとアプリ向けAPIとともに構築します。新しいコンポーネント、再利用可能なバックエンドモジュール、統合、またはコンポーネント境界の作業に使用します。
developmentdatabase
convex-migrate
get-convex
@convex-dev/migrationsを使用して、デプロイされたConvexアプリ上でスキーマの移行 + データのバックフィルを実行します。
developmentdatabase
convex-optimize
get-convex
既存のConvexアプリを監査および最適化:セキュリティ、スケーリング、アップグレード、可観測性。