Agent skill

Convex Release Audit

by udecode in udecode/kitcn

Audit newer Convex npm releases against kitcn. An agent skill from udecode/kitcn.

Apache-2.0Auto-check passedDevelopment

Install Convex Release Audit

skills CLI
$ npx skills add udecode/kitcn --skill convex-release-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install udecode/kitcn convex-release-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/udecode/kitcn.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/convex-release-audit .claude/skills/convex-release-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
convex-release-audit
GitHub stars
450
Token cost
~1.8k tokens
SKILL.md length
611 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit newer Convex npm releases against kitcn. An agent skill from udecode/kitcn.

  • Works in 7 steps: Establish Current And Target Versions → Read Both Changelogs → Read The Upstream Diff With gh → …
  • Checking whether a newer convex version unlocks kitcn improvements
  • SKILL.md covers Goal Template, Rules, 1. Establish Current And… and 2. Read Both Changelogs, plus 6 more sections
  • Calls git, rg and gh; reaches ship.convex.dev

What it does

Convex Release Audit is an agent skill from udecode/kitcn. Audit newer Convex npm releases against kitcn. Use when checking whether a newer convex version unlocks kitcn improvements, compatibility work, CLI/agent workflows, or cleanup of local Convex hacks. Reads https://ship.convex.dev/, the upstream Convex changelog, and GitHub diffs before delegating an implementation PR through task.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Changelog and release notes. It works with npm, Convex and GitHub. The repository describes itself as: Convex + Better Auth + tRPC + Drizzle + TanStack Query + shadcn. The licence is Apache-2.0.

When your agent uses it

  • Checking whether a newer convex version unlocks kitcn improvements
  • Compatibility work
  • CLI/agent workflows
  • Cleanup of local Convex hacks

Example prompts

  • “/convex-release-audit”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Establish Current And Target Versions
  2. Read Both Changelogs
  3. Read The Upstream Diff With gh
  4. Search Kitcn For Leverage
  5. Classify Opportunities
  6. Choose One PR Slice
  7. Delegate Through task

What it can do on your machine

Read from SKILL.md and the folder at commit c6010f5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • rg
    • gh
    • bun
    • node
    • npm
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • ship.convex.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Convex Release Audit loads about 1.8k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 611 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from udecode/kitcn at commit c6010f5, republished under its Apache-2.0 licence (© udecode). 611 words, ~1,817 tokens.

Download SKILL.mdSave it as .claude/skills/convex-release-audit/SKILL.md (or your agent's skills folder).
name
convex-release-audit
description
Audit newer Convex npm releases against kitcn. Use when checking whether a newer `convex` version unlocks kitcn improvements, compatibility work, CLI/agent workflows, or cleanup of local Convex hacks. Reads `https://ship.convex.dev/`, the upstream Convex changelog, and GitHub diffs before delegating an implementation PR through `task`.

Convex Release Audit

Handle $ARGUMENTS.

Goal: find newer Convex releases, extract work kitcn can actually use, then delegate one concrete implementation slice to $task so it opens the PR.

Goal Template

When this audit needs durable goal state, use the project-owned Convex release audit template instead of the generic task template:

bash
node .agents/skills/autogoal/scripts/create-goal-scratchpad.mjs \
  --template convex-release-audit \
  --title "convex release audit"

This plan owns version discovery, changelog reconciliation, upstream diff evidence, kitcn leverage classification, the selected slice or no-action verdict, and the delegated task prompt. Implementation still goes through task; do not duplicate implementation PR machinery inside the release-audit plan.

Rules

  • Use evidence, not vibes. Read both changelog sources and a diff.
  • Prefer deleting kitcn glue over adding more glue when upstream fixed the real problem.
  • Do not upgrade Convex just because a newer version exists. Ship only a leverageable improvement.
  • Keep the PR slice coherent. One release opportunity per PR unless multiple fixes share the same implementation boundary.
  • If no actionable opportunity exists, stop with the evidence. Do not open a vanity PR.

1. Establish Current And Target Versions

Find the currently pinned Convex version:

bash
rg -n '"convex":' package.json packages/**/package.json example/package.json

Find the latest published version:

bash
npm view convex version --json

If $ARGUMENTS names a target version, use it as the upper bound. Otherwise use the latest npm version.

Record:

  • current pinned version
  • target version
  • every version in the current-exclusive, target-inclusive range
  • exact package files that pin or constrain Convex

2. Read Both Changelogs

Read Ship:

bash
curl -sL https://ship.convex.dev/

Read the upstream npm package changelog through gh, not browser scraping:

bash
gh api \
  -H "Accept: application/vnd.github.raw" \
  repos/get-convex/convex-backend/contents/npm-packages/convex/CHANGELOG.md

Extract only the sections in range. Reconcile disagreements:

  • Ship is product-facing signal.
  • npm-packages/convex/CHANGELOG.md is package-facing signal.
  • If they disagree, keep both facts and investigate in the diff.

3. Read The Upstream Diff With gh

Use a local upstream clone for navigation, creating it only if missing:

bash
test -d ../convex-backend/.git || gh repo clone get-convex/convex-backend ../convex-backend
git -C ../convex-backend fetch origin main --tags

Find refs for the current and target versions. Prefer tags if they exist:

bash
git -C ../convex-backend tag -l "*<version>*" | sort
git -C ../convex-backend log --all --oneline -- npm-packages/convex/package.json

If tags are unclear, inspect version-bump commits in npm-packages/convex/package.json and use the commit before/after each version bump.

Read the compare through gh:

bash
gh api \
  repos/get-convex/convex-backend/compare/<base-ref>...<target-ref> \
  --jq '.files[] | select(.filename | test("npm-packages/convex|cli|agent|dev|auth|codegen|deployment|function|schema")) | {filename,status,patch}'

If the compare is too large, narrow locally after proving the refs:

bash
git -C ../convex-backend diff <base-ref>..<target-ref> -- \
  npm-packages/convex

4. Search Kitcn For Leverage

Search for local Convex integration points and hacks:

bash
rg -n "CONVEX_AGENT_MODE|local-force-upgrade|skip-push|typecheck disable|codegen disable|convex dev|convex init|convex run|CONVEX_|Convex" \
  packages www .agents docs test

Also search institutional notes before proposing work:

bash
rg -i --files-with-matches "convex|upgrade|agent|cli|dev|bootstrap|verify" docs/solutions

Read relevant hits, especially notes about:

  • local backend upgrade prompts
  • anonymous or non-interactive Convex setup
  • kitcn dev, kitcn verify, kitcn init
  • hidden Convex flags or leaked upstream plumbing
  • docs/skill sync for Convex setup guidance
Show full SKILL.md (227 more words)Show less

5. Classify Opportunities

For each release item, classify it:

  • feature: new Convex API, CLI command, runtime behavior, or platform feature kitcn can expose.
  • compatibility: required work to keep kitcn working with the new version.
  • agentic: upstream change that improves non-interactive, deterministic, or machine-readable flows.
  • cleanup: upstream change that lets kitcn delete a workaround, hidden flag, fake prompt handling, fallback path, or doc warning.
  • no-op: interesting upstream change with no kitcn action.

For every non-no-op, include:

  • changelog evidence
  • diff evidence
  • kitcn file(s) affected
  • expected implementation boundary
  • verification command(s)
  • confidence

Bias toward agentic and cleanup; kitcn exists to make Convex sharper for humans and agents, not to mirror every upstream bullet.

6. Choose One PR Slice

Pick the highest-leverage slice using this order:

  1. compatibility breakage
  2. delete dirty hack made obsolete upstream
  3. agentic CLI unlock
  4. product feature kitcn can expose cleanly
  5. docs or skill-only update

If the winning slice touches published package code, the delegated task must update the active changeset and run bun --cwd packages/kitcn build.

If it touches scaffold templates, the delegated task must run bun run fixtures:sync and bun run fixtures:check.

7. Delegate Through task

Load $task with a prompt in this exact shape:

md
Implement this Convex release opportunity.

Current Convex: <version>
Target Convex: <version>

Opportunity: <one-sentence selected slice>
Class: <feature | compatibility | agentic | cleanup>

Evidence:
- Ship changelog: <short citation or summary>
- Convex changelog: <short citation or summary>
- Upstream diff: <refs and files>
- Kitcn evidence: <local files and docs/solutions notes>

Implementation:
- <specific files or boundaries to inspect first>
- <expected code/doc/test shape>

Acceptance:
- <tests/checks>
- <package build if packages/kitcn changes>
- <fixtures commands if scaffold output changes>
- open the PR after verification

Do not preserve obsolete Convex workarounds if the upstream release removes the
need for them. Hard cut the hack.

Then follow task until the PR exists or a real blocker is proven.

Output

Before delegation, keep the audit terse:

md
Current: <version>
Target: <version>

| Class | Opportunity | Evidence | Decision |
| --- | --- | --- | --- |
| cleanup | ... | ... | selected |

Delegating to task: <selected slice>

After task finishes, use its final handoff format.

© udecode, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/convex-release-audit of udecode/kitcn.

Open the folder on GitHubat commit c6010f5

Compare with similar skills

Convex Release Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Convex Release Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Convex Release Audit this skilludecode/kitcn450—~1.8kAutomated safety check: PassApache-2.0
Cutting A ReleaseTriliumNext/Trilium38k—~3.2kAutomated safety check: PassAGPL-3.0
Verdaccio Pull Request Workflowverdaccio/verdaccio18k—~1.9kAutomated safety check: PassMIT
Version ReleaseNG-ZORRO/ng-zorro-antd9.2k—~3.1kAutomated safety check: PassMIT
Hunk Release Workflowmodem-dev/hunk9.5k—~3.8kAutomated safety check: PassMIT
Release Roundethereumjs/ethereumjs-monorepo2.8k—~2kAutomated safety check: PassNone

Similar skills

  • Cutting A Release

    TriliumNext/Trilium

    A skill your agent uses when cutting, preparing, or debugging a Trilium release — bumping the monorepo version, tagging, or diagnosing a failed "Release" workflow run.

    38k GitHub stars~3.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Takes a change through a verdaccio pull request: branch, local checks, changeset, title and body, labels, CI and review rounds, and ports to other release lines.

    18k GitHub stars~1.9k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Version Release

    NG-ZORRO/ng-zorro-antd

    NG-ZORRO/ng-zorro-antd repository release workflow. An agent skill from NG-ZORRO/ng-zorro-antd.

    9.2k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Hunk Release Workflow

    modem-dev/hunk

    Maintainer workflow for preparing, publishing, verifying and curating Hunk releases, with confirmation gates before tags, publishes and public edits.

    9.5k GitHub stars~3.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Release Round

    ethereumjs/ethereumjs-monorepo

    Runs a coordinated EthereumJS npm release round in six human-gated phases — intent and readiness, CHANGELOG, version bump, publish (human executes), post-publish verification, and announcements.

    2.8k GitHub stars~2k tokensUpdated 20 days ago
    DevelopmentAuto-check passed
  • Ccb GitHub

    SeemSeam/claude_codex_bridge

    Maintain this CCB project's GitHub-facing release and npm publication surface.

    3.6k GitHub stars~4.9k tokensUpdated today
    DevelopmentAuto-check passed

More from udecode/kitcn

All 33 skills in this repo
  • Walkthrough

    udecode/kitcn

    Create a short annotated visual walkthrough from real final-state screenshots or rendered artifacts.

    450 GitHub stars~1.6k tokensUpdated 7 days ago
    Auto-check passed
  • Avoid Feature Creep

    udecode/kitcn

    Prevent feature creep when building software, apps, and AI-powered products.

    450 GitHub stars~2.7k tokensUpdated 7 days ago
    Auto-check passed
  • Changeset Resolve

    udecode/kitcn

    Repair an unreleased .changeset/.md file so it matches the real branch delta against main.

    450 GitHub stars~922 tokensUpdated 7 days ago
    Auto-check passed
  • Jotai X

    udecode/kitcn

    A skill your agent uses when working with Jotai X stores (createAtomStore), accessing state in components or callbacks, persisting state to cookies or localStorage

    450 GitHub stars~3.7k tokensUpdated 7 days ago
    Auto-check passed
  • Linear Backlog

    udecode/kitcn

    Run a scoped Linear backlog autonomously as a sequence of maximal safe parallel batches by composing orchestrator, autogoal, and task.

    450 GitHub stars~3.1k tokensUpdated 7 days ago
    Auto-check passed
  • Nextjs

    udecode/kitcn

    Next.js routing with typed routes, PageProps, LayoutProps helpers, and nuqs for URL state.

    450 GitHub stars~1.4k tokensUpdated 7 days ago
    Auto-check passed

Works with

Categories

Questions about Convex Release Audit

What does Convex Release Audit do?

Audit newer Convex npm releases against kitcn. An agent skill from udecode/kitcn. Convex Release Audit is an agent skill from udecode/kitcn. Audit newer Convex npm releases against kitcn.

When should I use Convex Release Audit?

Convex Release Audit fits situations like: checking whether a newer convex version unlocks kitcn improvements; compatibility work; CLI/agent workflows; cleanup of local Convex hacks.

How do I install Convex Release Audit in Claude Code?

Run `npx skills add udecode/kitcn --skill convex-release-audit -a claude-code`. Or copy the skill folder (.agents/skills/convex-release-audit in udecode/kitcn) into .claude/skills/convex-release-audit in your project. Claude Code loads it when a task matches its description.

How do I install Convex Release Audit in Codex?

Run `npx skills add udecode/kitcn --skill convex-release-audit -a codex`. Or copy the skill folder (.agents/skills/convex-release-audit in udecode/kitcn) into .agents/skills/convex-release-audit in your project. Codex loads it when a task matches its description.

Can I use Convex Release Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add udecode/kitcn --skill convex-release-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/convex-release-audit, .gemini/skills/convex-release-audit, .github/skills/convex-release-audit and .opencode/skills/convex-release-audit in your project.

What does Convex Release Audit need to run?

Going by SKILL.md and its folder, Convex Release Audit needs the command-line tools its instructions call (git, rg, gh, bun, node and npm).

Does Convex Release Audit access the network?

SKILL.md names 1 domain. In commands or code: ship.convex.dev; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Convex Release Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Convex Release Audit use?

Convex Release Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Convex Release Audit use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Convex Release Audit?

Skills that share tags, products or a category with Convex Release Audit: Cutting A Release (TriliumNext/Trilium, 38k stars), Verdaccio Pull Request Workflow (verdaccio/verdaccio, 18k stars), Version Release (NG-ZORRO/ng-zorro-antd, 9.2k stars) and Hunk Release Workflow (modem-dev/hunk, 9.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Convex Release Audit?

udecode (a GitHub organization) maintains it in udecode/kitcn, which has 450 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 1, 2026.

Source: udecode/kitcn on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.