skills/convex-audit/SKILL.md
Audit Convex—schema, security, runtime edges, migrations, function risk. Triggers—review, contract, remediate. Not greenfield spec (convex-feature-spec).
npx skillsauth add bjornmelin/dev-skills convex-auditInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use this skill for read-first Convex audits that produce a clear remediation plan before implementation.
AGENTS.md./home/bjorn/.codex/skill-support/bin/convex-scan inventory --cwd <repo> --out <json>./home/bjorn/.codex/skill-support/bin/convex-scan surface --cwd <repo> --out <json>./home/bjorn/.codex/skill-support/bin/convex-scan gaps --inventory <json> --out <json>.references/security.mdreferences/schema.mdreferences/runtime-boundaries.mdreferences/migrations.md/home/bjorn/.codex/skill-support/bin/convex-scanreferences/security.mdreferences/schema.mdreferences/runtime-boundaries.mdreferences/migrations.mddevelopment
Pre-PR multi-model review, parallel opus and codex exec adversarial lanes, then adversarial verification of merged findings. Read-only. Use before shipping nontrivial diffs.
tools
Independent gpt-5.6 diff review via the Codex CLI, normal or steerable adversarial with JSON findings. Use before shipping nontrivial changes.
development
Delegate implementation, investigation, or bulk work to gpt-5.6 codex via pinned codex exec. Use for clear-spec builds, migrations, debugging, or any task MODELS.md routes to codex.
development
Adversarial pre-mortem: imagine the plan failed, work backwards to surface risky assumptions + irreversible bets, then harden them. Proactively offer it (after the current request; confirm first) before a hard-to-reverse or one-way-door call (API, schema, framework, a hire), an all-upside plan, or unvalidated assumptions. Also on request.