Agent Skills
› openclaw/clawhub
› convex-reviewer
convex-reviewer
GitHubConvex代码审查工具,专注于安全、认证、验证器、性能及模式检查。通过结构化流程审计Convex函数,识别反模式并按严重程度报告问题,确保代码在发布前符合最佳实践。
Trigger Scenarios
审查Convex目录下的代码
发布前对Convex函数进行审计
检查安全与性能隐患
Install
npx skills add openclaw/clawhub --skill convex-reviewer -g -y
SKILL.md
Frontmatter
{
"name": "convex-reviewer",
"description": "Convex code reviewer — security, auth, validators, performance, and pattern checks for code in a convex\/ directory. Use to review or audit Convex functions before shipping."
}
Convex Code Reviewer
Structured review of Convex code for security, authorization, validators, performance, and schema design. Applies a Convex-specific checklist and flags anti-patterns with severity (Critical / Important / Suggestion).
Workflow
- First pass — Security: verify all public functions check ctx.auth.getUserIdentity(), verify resource ownership before reads/writes, confirm no client-provided user IDs are trusted, confirm scheduled functions target internal.* not api.*.
- Second pass — Performance: confirm no .filter() on DB queries (withIndex required), verify all foreign-key fields have indexes, confirm no Date.now() in query handlers, confirm .collect() is not used on unbounded queries.
- Third pass — Code quality: confirm args and returns validators on every public function, no any types, promises are awaited, arrays in documents are bounded (<8192 elements).
- Report findings grouped by severity; explain why each issue matters and suggest a fix.
Rules
- Flag missing auth checks as Critical — any unauthenticated public mutation is a data-loss risk.
- Flag .filter() on DB queries as Important — it is a full table scan.
- Flag Date.now() in query handlers as Important — it breaks reactivity.
- Flag missing args or returns validators as Important.
- Flag scheduling to api.* (not internal.*) as Important.
- Always explain why a change is needed, not just what to change.
Version History
- d6a8c68 Current 2026-08-20 02:44


