Agent skill

Convex Verify

by openclaw in openclaw/clawhub

Prove a Convex feature works — seed, drive as multiple mocked users via convex-test, assert behavior including the negative authz cases (wrong user refused, data-scope enforced).

MITAuto-check passedBackend & APIs

Install Convex Verify

skills CLI
$ npx skills add openclaw/clawhub --skill convex-verify -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/clawhub convex-verify --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/clawhub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/convex-verify .claude/skills/convex-verify && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
convex-verify
GitHub stars
9.5k
Token cost
~1.2k tokens
SKILL.md length
664 words
Files
1
Skills in repo
56
Repo updated
First seen
Licence
MIT

At a glance

Prove a Convex feature works — seed, drive as multiple mocked users via convex-test, assert behavior including the negative authz cases (wrong user refused, data-scope enforced).

  • Works in 7 steps: IDENTIFY the feature to prove: the… → SET UP convex-test: ensure convex-test +… → SEED realistic data through the app's… → …
  • Tasks that involve Authorization and RBAC
  • SKILL.md covers Workflow and Rules
  • Calls npx

What it does

Convex Verify is an agent skill from openclaw/clawhub. Prove a Convex feature works — seed, drive as multiple mocked users via convex-test, assert behavior including the negative authz cases (wrong user refused, data-scope enforced).

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC. The repository describes itself as: Skill + Plugin Registry for OpenClaw. The licence is MIT.

When your agent uses it

  • Tasks that involve Authorization and RBAC

Example prompts

  • “/convex-verify”

Requirements

  • Node.js

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. IDENTIFY the feature to prove: the specific exported query/mutation/action (or a small set) the user just built/changed, and its intended…
  2. SET UP convex-test: ensure convex-test + vitest are dev deps AND a vitest.config.ts sets test.environment: "edge-runtime" with…
  3. SEED realistic data through the app's OWN functions where possible (so the seed exercises the same validators/mutations a real user…
  4. DRIVE the feature as DIFFERENT identities with t.withIdentity({ subject, tokenIdentifier, ... }): call the function as (a) the legitimate…
  5. ASSERT behavior — POSITIVE and NEGATIVE
  6. RUN the tests (npx vitest run) and report: what was proven (each positive + negative assertion that passed), and — critically — any…
  7. Do NOT weaken a test to make it pass: if the owner-only query returns another user's row, the FIX is in the function (hand to…

What it can do on your machine

Read from SKILL.md and the folder at commit c23e34a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Convex Verify loads about 1.2k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 664 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openclaw/clawhub at commit c23e34a, republished under its MIT licence (© openclaw). 664 words, ~1,231 tokens.

Download SKILL.mdSave it as .claude/skills/convex-verify/SKILL.md (or your agent's skills folder).
name
convex-verify
description
Prove a Convex feature works — seed, drive as multiple mocked users via convex-test, assert behavior including the negative authz cases (wrong user refused, data-scope enforced).
<!-- GENERATED from convex-agents content/capabilities/convex-verify.json — do not edit by hand. -->

Prove a feature works — seed, drive, assert

A green typecheck proves the code parses; it does not prove a non-owner is actually denied, that a query returns the right rows, or that a mutation has the effect it claims. This capability closes that gap with the loop the whole field is missing: seed → drive → assert, run in-process with convex-test so it needs no deployment. Its highest-value assertions are the NEGATIVE ones — the caller who should be refused — because those are exactly the authz defects the 30-app corpus shows are the #1 real bug and the ones a happy-path demo never catches.

Workflow

  1. IDENTIFY the feature to prove: the specific exported query/mutation/action (or a small set) the user just built/changed, and its intended behavior — who should be allowed, what data should come back, what a mutation should change. If the intent is unstated, ask one focused question rather than guessing the contract.
  2. SET UP convex-test: ensure convex-test + vitest are dev deps AND a vitest.config.ts sets test.environment: "edge-runtime" with server.deps.inline: ["convex-test"] — WITHOUT that config, convexTest(schema) fails at runtime with import.meta.glob is not a function (verified). Also install @edge-runtime/vm. Then convexTest(schema) gives a t handle. Reuse the project's existing test setup if present (compose with the test capability, don't fork it).
  3. SEED realistic data through the app's OWN functions where possible (so the seed exercises the same validators/mutations a real user would), falling back to t.run(async (ctx) => ctx.db.insert(...)) for fixtures the public API can't create. Seed at least: the caller's own rows AND a second user's rows, so cross-user access is testable.
  4. DRIVE the feature as DIFFERENT identities with t.withIdentity({ subject, tokenIdentifier, ... }): call the function as (a) the legitimate owner, (b) a different authenticated user, and (c) unauthenticated (t with no identity). Use the real identity shape the app's auth uses (subject/tokenIdentifier), matching how ownership is resolved.
  5. ASSERT behavior — POSITIVE and NEGATIVE:
    • positive: the owner gets the expected rows / the mutation made the expected change (expect(await t.withIdentity(owner).query(api.x.y, args)).toEqual(...)).
    • NEGATIVE (the load-bearing half): a different user calling the same function is REFUSED — await expect(t.withIdentity(other).mutation(api.x.cancel, {id})).rejects.toThrow(/forbidden|not authorized|403/) — and an unauthenticated caller is refused where auth is required. A feature is not proven until the wrong caller is shown to be blocked.
    • data-scope: a list/query returns ONLY the caller's rows, never the second user's (assert the second user's row is absent).
  6. RUN the tests (npx vitest run) and report: what was proven (each positive + negative assertion that passed), and — critically — any assertion that FAILED, because a failed negative assertion is a real authz hole found before ship. Emit findings on the bus (specs/finding.schema.json, class authz/correctness, evidence kind probe-result with the exact failing call) for anything that didn't behave.
  7. Do NOT weaken a test to make it pass: if the owner-only query returns another user's row, the FIX is in the function (hand to convex-authz), not in the assertion. A test changed until it's green proves nothing.
Show full SKILL.md (177 more words)Show less

Rules

  • Prove behavior, not compilation: every verification includes at least one NEGATIVE assertion (a caller who should be refused is refused) — the happy path alone is not proof.
  • Drive the feature as multiple identities with t.withIdentity (owner, other user, unauthenticated) using the app's real subject/tokenIdentifier shape.
  • Seed both the caller's rows AND a second user's rows so cross-user access and data-scope are actually testable.
  • A vitest.config.ts with environment 'edge-runtime' + convex-test inlined is REQUIRED for convex-test to run (import.meta.glob needs it); author it, don't just author the test file.
  • Run in-process with convex-test — no deployment needed; compose with the test capability's setup rather than forking it.
  • Never weaken an assertion to make it pass: a failing negative test is a real defect → hand the fix to convex-authz/convex-expert, don't edit the test until it's green.
  • Emit a bus finding for any assertion that failed (authz/correctness, evidence: the failing probe call) so a composite pass or self-heal can pick it up.
  • This drives a SPECIFIC built feature; a request to set up a test framework generally is the test capability.

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/convex-verify of openclaw/clawhub.

Open the folder on GitHubat commit c23e34a

Compare with similar skills

Convex Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Convex Verify compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Convex Verify this skillopenclaw/clawhub9.5k—~1.2kAutomated safety check: PassMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
K8s Security PoliciesCybereason-Public/owLSM28012 repos~2kAutomated safety check: PassGPL-2.0
Payloadpayloadcms/payload45k5 repos~6.2kAutomated safety check: PassMIT
Convex Setup Authspokvulcan/poker-planning1148 repos~1.8kAutomated safety check: PassMIT
Abp Authorizationabpframework/abp14k—~1.3kAutomated safety check: PassLGPL-3.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • K8s Security Policies

    Cybereason-Public/owLSM

    Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

    280 GitHub starsUsed in 12 repos~2k tokens
    Backend & APIsAuto-check passed
  • Payload

    payloadcms/payload

    A skill your agent uses when working with Payload projects (payload.config.ts, collections, fields, hooks, access control, Payload API).

    45k GitHub starsUsed in 5 repos~6.2k tokens
    Backend & APIsAuto-check passed
  • Convex Setup Auth

    spokvulcan/poker-planning

    Sets up Convex auth, identity mapping, and access control. An agent skill from spokvulcan/poker-planning.

    114 GitHub starsUsed in 8 repos~1.8k tokens
    Backend & APIsAuto-check passed
  • Abp Authorization

    abpframework/abp

    ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.

    14k GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • UI Audit

    bagofwords1/bagofwords

    Exhaustively audit the UI control by control and role by role — enumerate every button, link, and input on a set of pages, write down what each is supposed to do (derived from the handler code and…

    458 GitHub stars~2.9k tokensUpdated today
    Backend & APIsAuto-check passed

More from openclaw/clawhub

All 56 skills in this repo
  • Creates and manages Axiom monitors and notifiers end to end through the v2 API, with scripts for each CRUD operation and a recommended create-validate-tune workflow.

    9.5k GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • Axiom Dashboard Builder

    openclaw/clawhub

    Designs and deploys Axiom dashboards through the API, choosing chart types and writing APL or metrics queries, with templates and migration notes for Splunk and Grafana.

    9.5k GitHub stars~4.9k tokensUpdated yesterday
    Auto-check passed
  • Axiom Cost Control

    openclaw/clawhub

    Finds unused data in Axiom by analyzing query patterns, then deploys a cost dashboard and ingest monitors to keep spend under the contract limit.

    9.5k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Axiom Metrics Query

    openclaw/clawhub

    Explores and queries OpenTelemetry metrics in Axiom MetricsDB, listing datasets, metrics and tags first and picking the right aggregation for each metric's type.

    9.5k GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Axiom SRE Investigator

    openclaw/clawhub

    Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.

    9.5k GitHub stars~7.1k tokensUpdated yesterday
    Auto-check passed
  • Axiom Eval Writer

    openclaw/clawhub

    Scaffolds evaluation suites for the Axiom AI SDK: eval files, scorers, flag schemas and axiom.config.ts, generated from plain descriptions of an AI capability.

    9.5k GitHub stars~4.1k tokensUpdated yesterday
    Auto-check: warnings

Categories

Questions about Convex Verify

What does Convex Verify do?

Prove a Convex feature works — seed, drive as multiple mocked users via convex-test, assert behavior including the negative authz cases (wrong user refused, data-scope enforced). Convex Verify is an agent skill from openclaw/clawhub. Prove a Convex feature works — seed, drive as multiple mocked users via convex-test, assert behavior including the negative authz cases (wrong user refused, data-scope enforced).

When should I use Convex Verify?

Convex Verify fits situations like: tasks that involve Authorization and RBAC.

How do I install Convex Verify in Claude Code?

Run `npx skills add openclaw/clawhub --skill convex-verify -a claude-code`. Or copy the skill folder (.agents/skills/convex-verify in openclaw/clawhub) into .claude/skills/convex-verify in your project. Claude Code loads it when a task matches its description.

How do I install Convex Verify in Codex?

Run `npx skills add openclaw/clawhub --skill convex-verify -a codex`. Or copy the skill folder (.agents/skills/convex-verify in openclaw/clawhub) into .agents/skills/convex-verify in your project. Codex loads it when a task matches its description.

Can I use Convex Verify in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/clawhub --skill convex-verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/convex-verify, .gemini/skills/convex-verify, .github/skills/convex-verify and .opencode/skills/convex-verify in your project.

What does Convex Verify need to run?

Going by SKILL.md and its folder, Convex Verify needs the command-line tools its instructions call (npx). Our summary lists: Node.js.

Does Convex Verify access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Convex Verify safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Convex Verify use?

Convex Verify is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Convex Verify use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Convex Verify?

Skills that share tags, products or a category with Convex Verify: Configuring Horizon (coollabsio/coolify, 63k stars), K8s Security Policies (Cybereason-Public/owLSM, 280 stars), Payload (payloadcms/payload, 45k stars) and Convex Setup Auth (spokvulcan/poker-planning, 114 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Convex Verify?

openclaw (a GitHub organization) maintains it in openclaw/clawhub, which has 9,495 GitHub stars. The repository holds 56 skills in this directory. The repository was last updated on October 7, 2026.

Source: openclaw/clawhub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.