Grails Violation Fixer
apache/grails-core
Guide to running, reading and fixing code style and analysis violations in grails-core with CodeNarc, Checkstyle, PMD, SpotBugs, Spotless and JaCoCo through Gradle.
Run convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories.
$ npx skills add waynesutton/markdown-site --skill convex-doctor -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install waynesutton/markdown-site convex-doctor --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/waynesutton/markdown-site.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/convex-doctor .claude/skills/convex-doctor && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "convex-doctor" agent skill from https://github.com/waynesutton/markdown-site/tree/main/.cursor/skills/convex-doctor into .claude/skills/convex-doctor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "convex-doctor", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/waynesutton/markdown-site/tree/main/.cursor/skills/convex-doctorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add waynesutton/markdown-site --skill convex-doctor -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install waynesutton/markdown-site convex-doctor --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/waynesutton/markdown-site.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.cursor/skills/convex-doctor .agents/skills/convex-doctor && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "convex-doctor" agent skill from https://github.com/waynesutton/markdown-site/tree/main/.cursor/skills/convex-doctor into .agents/skills/convex-doctor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "convex-doctor", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add waynesutton/markdown-site --skill convex-doctor -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install waynesutton/markdown-site convex-doctor --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/waynesutton/markdown-site.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.cursor/skills/convex-doctor .cursor/skills/convex-doctor && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "convex-doctor" agent skill from https://github.com/waynesutton/markdown-site/tree/main/.cursor/skills/convex-doctor into .cursor/skills/convex-doctor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "convex-doctor", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/waynesutton/markdown-site.git --path .cursor/skills/convex-doctor--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add waynesutton/markdown-site --skill convex-doctor -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install waynesutton/markdown-site convex-doctor --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/waynesutton/markdown-site.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.cursor/skills/convex-doctor .gemini/skills/convex-doctor && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "convex-doctor" agent skill from https://github.com/waynesutton/markdown-site/tree/main/.cursor/skills/convex-doctor into .gemini/skills/convex-doctor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "convex-doctor", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install waynesutton/markdown-site convex-doctorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add waynesutton/markdown-site --skill convex-doctor -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/waynesutton/markdown-site.git skills-src && mkdir -p .github/skills && cp -r skills-src/.cursor/skills/convex-doctor .github/skills/convex-doctor && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "convex-doctor" agent skill from https://github.com/waynesutton/markdown-site/tree/main/.cursor/skills/convex-doctor into .github/skills/convex-doctor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "convex-doctor", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add waynesutton/markdown-site --skill convex-doctor -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install waynesutton/markdown-site convex-doctor --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/waynesutton/markdown-site.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.cursor/skills/convex-doctor .opencode/skills/convex-doctor && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "convex-doctor" agent skill from https://github.com/waynesutton/markdown-site/tree/main/.cursor/skills/convex-doctor into .opencode/skills/convex-doctor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "convex-doctor", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
convex-doctorRun convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories.
Convex Doctor is an agent skill from waynesutton/markdown-site. Run convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories. Use when running convex-doctor, fixing convex-doctor warnings or errors, improving the convex-doctor score, or when asked about Convex code quality, static analysis, or linting Convex functions.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Static analysis and SAST, Linting and formatting and Code quality. The repository describes itself as: An open-source publishing framework built for AI agents and developers to ship websites, docs, or blogs. Write markdown, sync from the terminal. Your content is instantly… The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 3872c59. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npxnpmFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Convex Doctor loads about 1.9k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 871 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from waynesutton/markdown-site at commit 3872c59, republished under its MIT licence (© waynesutton). 871 words, ~1,855 tokens.
.claude/skills/convex-doctor/SKILL.md (or your agent's skills folder).This skill codifies the full convex-doctor remediation workflow used in this codebase (score 42 to 100 across 17 passes). Follow it whenever running convex-doctor or fixing its findings.
convex-doctor is a static analysis tool for Convex backends. It scores your codebase 0 to 100 across five categories: security, correctness, performance, schema, and architecture.
Run it with:
npx convex-doctor@latestThis project has a convex-doctor.toml at the repo root with intentional suppressions. Always check it before working on findings.
| Rule | Level | Rationale |
|---|---|---|
correctness/generated-code-modified | off | Working tree is always dirty after codegen |
schema/optional-field-no-default-handling | off | 94 optional fields by design for markdown frontmatter |
correctness/missing-unique | off | Remaining .first() calls are intentional ordered picks |
schema/deep-nesting | off | 4-level validators needed for chat attachments |
schema/array-relationships | off | Flagged on function args, not table columns |
perf/missing-index-on-foreign-key | off | Remaining FK is inside nested array (not indexable) |
arch/duplicated-auth | off | Auth awareness is intentional per public handler |
arch/monolithic-file | off | Files organized by domain |
arch/large-handler | off | Email templates, sync, and search are inherently multi-step |
convex/_generated/** (generated code)convex/authComponent.ts (thin auth component forwarders)When convex-doctor reports findings, fix them in this order:
Security errors (highest priority)
api.* server-to-server calls to internal.*Correctness errors
Date.now() from queries (breaks caching and reactivity).first() to .unique() only where the index enforces uniquenesscollect then filter patterns with indexed queriesPerformance warnings
.collect() with .take(n) or paginationctx.run* calls into single internal queriesSchema warnings
by_field snake_case conventionArchitecture warnings
throw new Error(...) with ConvexError in user-facing handlersInstead of calling a public action from the browser, create a job table and mutation-scheduled internal action:
convex/schema.ts with status, result, and error fieldsinternalAction that updates the job record on completion or failureThis pattern was used for: AI image generation, AI chat responses, URL imports.
When a Convex function calls another Convex function on the server side:
internal* version if only a public version existsapi.module.fn with internal.module.fn in the callerWhen an action makes multiple ctx.runQuery calls for independent data:
ctx.runQuery to the batched querysequential-run-calls warningQueries must be deterministic. Replace Date.now() with a timestamp argument:
now: v.number() argument to the queryDate.now() from the frontend or from the action/mutation that calls the queryWhen components.auth.public.* triggers direct-function-ref warnings:
convex/authComponent.ts that call the component APIctx.runQuery(internal.authComponent.*)convex/authComponent.ts to the [ignore] section of convex-doctor.tomlAfter every fix pass:
npx convex codegen passesnpx tsc --noEmit passes (or npx convex codegen covers this)npm run build succeedsnpx convex-doctor@latest shows improved score or fewer findings| Pass | Score | Errors | Warnings | Key changes |
|---|---|---|---|---|
| Initial | 42/100 | 73 | 243 | Baseline |
| 1 (remediation) | ~55 | ~50 | ~221 | Security: auth on HTTP, api to internal |
| 2 | ~60 | ~40 | ~200 | AI action flow, HTTP hardening |
| 3 | 68/100 | - | - | collect-then-filter, auth signals |
| 10 | 80/100 | 1 | 68 | Import URL queued job, unique lookups |
| 15 | 91/100 | 0 | 43 | Newsletter batching, auth forwarders, toml config |
| 16 | 92/100 | 0 | 39 | Semantic search batching, auth helpers |
| 17 | 100/100 | 0 | 0 | Stats helpers, contact helpers, final toml tuning |
Fix it when:
Suppress it when:
Always document suppressions with rationale in convex-doctor.toml.
All remediation PRDs are in prds/convex-doctor/:
convex-doctor-remediation.md (initial plan, 5 phases)convex-doctor-second-pass.md through convex-doctor-seventeenth-pass.mdconvex-doctor.toml (suppression config)convex/schema.ts (indexes and table definitions)convex/authComponent.ts (auth component forwarders)convex/importJobs.ts (queued job pattern example)convex/aiImageJobs.ts (queued job pattern example)convex/semanticSearchJobs.ts (queued job pattern example)© waynesutton, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .cursor/skills/convex-doctor of waynesutton/markdown-site.
Open the folder on GitHubat commit 3872c59
Convex Doctor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Convex Doctor this skillwaynesutton/markdown-site | 627 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Grails Violation Fixerapache/grails-core | 2.9k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Code Qualitybonny/WordPress-Simple-History | 317 | — | ~519 | Automated safety check: Notes | None | |
| Code QualityBlackBeltTechnology/pi-agent-dashboard | 315 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Dx Code Analyzer Runforcedotcom/sf-skills | 1.1k | — | ~6.3k | Automated safety check: Pass | Apache-2.0 | |
| Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop | 5.4k | — | ~2.2k | Automated safety check: Pass | MIT |
apache/grails-core
Guide to running, reading and fixing code style and analysis violations in grails-core with CodeNarc, Checkstyle, PMD, SpotBugs, Spotless and JaCoCo through Gradle.
bonny/WordPress-Simple-History
Runs linting and static analysis on PHP/CSS/JS using phpcs, phpstan, and rector.
BlackBeltTechnology/pi-agent-dashboard
Drive static-analysis code quality in pi-agent-dashboard with Biome (analyze → fix → test), in changed-files or whole-repo mode.
forcedotcom/sf-skills
Run Salesforce Code Analyzer to scan code for security, performance, best practice, and code style violations.
dmmulroy/anti-slop
Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.
comet-ml/opik
Checklist for wiring a new linter into Opik's Code Quality pipeline: the four files to edit, the silent-failure gotchas and the pass/fail verification loop.
waynesutton/markdown-site
Integrate Convex static self hosting into existing apps using the latest upstream instructions from get-convex/self-hosting every time.
waynesutton/markdown-site
Integrate and maintain Robelest Convex Auth in apps by always checking upstream before implementation.
waynesutton/markdown-site
Plan and execute Convex schema migrations safely, including adding fields, creating tables, and data transformations.
waynesutton/markdown-site
Guide for when to use and when not to use return validators in Convex functions.
waynesutton/markdown-site
Initialize a new Convex project from scratch or add Convex to an existing app.
waynesutton/markdown-site
Set up Convex authentication with proper user management, identity mapping, and access control patterns.
Categories
Run convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories. Convex Doctor is an agent skill from waynesutton/markdown-site. Run convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories.
Convex Doctor fits situations like: running convex-doctor; fixing convex-doctor warnings; improving the convex-doctor score; asked about Convex code quality.
Run `npx skills add waynesutton/markdown-site --skill convex-doctor -a claude-code`. Or copy the skill folder (.cursor/skills/convex-doctor in waynesutton/markdown-site) into .claude/skills/convex-doctor in your project. Claude Code loads it when a task matches its description.
Run `npx skills add waynesutton/markdown-site --skill convex-doctor -a codex`. Or copy the skill folder (.cursor/skills/convex-doctor in waynesutton/markdown-site) into .agents/skills/convex-doctor in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add waynesutton/markdown-site --skill convex-doctor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/convex-doctor, .gemini/skills/convex-doctor, .github/skills/convex-doctor and .opencode/skills/convex-doctor in your project.
Going by SKILL.md and its folder, Convex Doctor needs the command-line tools its instructions call (npx and npm). Our summary lists: Node.js.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Convex Doctor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Convex Doctor: Grails Violation Fixer (apache/grails-core, 2.9k stars), Code Quality (bonny/WordPress-Simple-History, 317 stars), Code Quality (BlackBeltTechnology/pi-agent-dashboard, 315 stars) and Dx Code Analyzer Run (forcedotcom/sf-skills, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
waynesutton (a GitHub user) maintains it in waynesutton/markdown-site, which has 627 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on May 20, 2026.
Source: waynesutton/markdown-site on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.