Agent skill

Convex Security Audit

by waynesutton in waynesutton/builder-skills

Deep security review of a Convex app: authorization model, data access paths per table, HTTP action exposure, rate limiting, file storage access, scheduled function trust, and a written findings…

Apache-2.0Auto-check passedSecurity

Install Convex Security Audit

skills CLI
$ npx skills add waynesutton/builder-skills --skill convex-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install waynesutton/builder-skills convex-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/waynesutton/builder-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/convex-security-audit .claude/skills/convex-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
convex-security-audit
GitHub stars
406
Token cost
~2.6k tokens
SKILL.md length
1,189 words
Files
7 (incl. references, assets)
Skills in repo
17
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deep security review of a Convex app: authorization model, data access paths per table, HTTP action exposure, rate limiting, file storage access, scheduled function trust, and a written findings…

  • Works in 8 steps: Inventory public functions → Map auth per function → Map data access per table → …
  • Asks for a full audit rather than a quick check
  • SKILL.md covers When to reach for this, Reference files, Audit procedure and Severity scale, plus 4 more sections
  • Calls rg and npx

What it does

Convex Security Audit is an agent skill from waynesutton/builder-skills. Deep security review of a Convex app: authorization model, data access paths per table, HTTP action exposure, rate limiting, file storage access, scheduled function trust, and a written findings report. Use before launch, after an incident, or when the user asks for a full audit rather than a quick check.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files and assets (for example `agents/openai.yaml`, `references/attack-surface.md` and `references/audit-report-template.md`).

It sits in Security, covering Security review, File uploads and storage and Rate limiting. The repository describes itself as: Builder skills for Convex apps. Convex patterns plus a PRD, task.md, changelog, and files.md workflow for Claude Code, Codex, Cursor, and OpenCode. The licence is Apache-2.0.

When your agent uses it

  • Asks for a full audit rather than a quick check
  • Tasks that involve Security review
  • Tasks that involve File uploads and storage

Example prompts

  • “/convex-security-audit”

Requirements

  • Node.js

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Inventory public functions
  2. Map auth per function
  3. Map data access per table
  4. Review http.ts
  5. Review file storage
  6. Review scheduled and internal boundaries
  7. Review env and secrets
  8. Write the report

What it can do on your machine

Read from SKILL.md and the folder at commit 82d1ce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.convex.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Convex Security Audit loads about 2.6k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 1,189 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from waynesutton/builder-skills at commit 82d1ce2, republished under its Apache-2.0 licence (© waynesutton). 1,189 words, ~2,555 tokens.

Download SKILL.mdSave it as .claude/skills/convex-security-audit/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
convex-security-audit
description
Deep security review of a Convex app: authorization model, data access paths per table, HTTP action exposure, rate limiting, file storage access, scheduled function trust, and a written findings report. Use before launch, after an incident, or when the user asks for a full audit rather than a quick check.

Convex security audit

Produces a written findings report covering every public function, every table, and every entry point (HTTP routes, file storage, scheduler). The one rule: every exported query, mutation, and action is a public endpoint anyone on the internet can call with any arguments, so each one must prove who the caller is and what they may touch.

For a ten minute pass, use convex-security-check instead. This skill is the slow, complete version.

When to reach for this

  • Before a production launch or a major release
  • After an incident, a leaked key, or suspicious data access
  • When the codebase has grown past a handful of public functions and nobody has mapped who can call what
  • When adding multi tenant, admin, or billing features
  • When the user asks for "a full audit", "security review", or "check the whole backend"

Reference files

  • references/authorization-patterns.md: open when fixing findings, it has the getCurrentUser helper, customQuery and customMutation wrappers for authed, admin, and tenant scoped access, ownership checks through indexes, and role checks.
  • references/attack-surface.md: open during steps 4 through 7, it covers HTTP actions, storage URL leakage, scheduler trust, rate limiting with @convex-dev/rate-limiter, secrets in env, and client supplied IDs.
  • references/audit-report-template.md: open at step 8, it is the findings template and the per table data access matrix to fill in.

Audit procedure

Work through the steps in order. Record every finding as you go. Do not fix anything until the inventory is complete; fixing early hides the shape of the problem.

1. Inventory public functions

List every exported query, mutation, and action. These are the attack surface.

bash
rg -n "export const \w+ = (query|mutation|action)\(" convex --glob '!**/_generated/**'

For each one write down: file, name, type, whether a client needs to call it, and whether it is costly (sends email, calls an LLM, creates records) and so needs a rate limit. Anything only called by other Convex functions, crons, or the scheduler should be internalQuery, internalMutation, or internalAction. Flag each of those as a finding.

2. Map auth per function

For every public function from step 1, answer: does it call ctx.auth.getUserIdentity() (or a helper that does) before reading or writing? Which functions are intentionally anonymous?

bash
rg -l "= (query|mutation|action)\(" convex --glob '!**/_generated/**' \
  | xargs rg -L "getUserIdentity|getCurrentUser|authedQuery|authedMutation"

Files that print here contain public functions with no auth call anywhere in the file. Read each one. Anonymous is fine for a public blog list. It is a critical finding for anything that returns or writes user data.

Check that auth helpers throw or return early on a missing identity, and that role checks read the role from your users table, not from client arguments.

3. Map data access per table

For every table in convex/schema.ts, list which public functions read it, which write it, and what condition scopes the access (owner ID, org membership, role, public flag). Fill in the data access matrix from the report template.

Look for:

  • Reads with no scoping: ctx.db.query("table").collect() inside a public function
  • ctx.db.get(args.someId) followed by a return or patch with no ownership comparison
  • Ownership compared against a spoofable value (email, display name) instead of user._id
  • .filter() used for scoping instead of .withIndex(); this usually means the scoping was an afterthought
  • Return validators that leak fields: v.any(), or spreading a full document that carries passwordHash, stripeCustomerId, or internal flags
bash
rg -n "v\.any\(\)" convex --glob '!**/_generated/**'
rg -n "ctx\.db\.(get|patch|delete|replace)\(args\." convex --glob '!**/_generated/**'
4. Review http.ts

Every route in convex/http.ts is reachable without a Convex client. For each route check: how is the caller verified (webhook signature, bearer token, ctx.auth.getUserIdentity()), is the body validated before use, and does it call only internal.* functions with data it has already verified?

bash
rg -n "http\.route|httpAction\(" convex/http.ts

Webhook handlers that skip signature verification are critical. Routes that call api.* functions from inside an httpAction may be bypassing auth those functions assume they have.

5. Review file storage

Find where upload URLs are generated and where file URLs are returned.

bash
rg -n "storage\.(generateUploadUrl|getUrl|delete)" convex --glob '!**/_generated/**'

generateUploadUrl in a public mutation with no auth lets anyone fill your storage. A query that returns ctx.storage.getUrl(args.fileId) for any ID the client passes is a data leak; the URL works for anyone who holds it.

6. Review scheduled and internal boundaries

Internal functions skip auth by design. The question is whether anything schedules them with unverified input.

bash
rg -n "(runAfter|runAt|runMutation|runAction|interval|cron)\([^)]*\bapi\." convex --glob '!**/_generated/**'

Scheduling an api.* function is a finding: use internal.*. Then trace each internal.* call site back to the public function or route that triggered it and confirm the caller validated ownership before scheduling.

Show full SKILL.md (483 more words)Show less
7. Review env and secrets
bash
rg -n -i "(sk_live|sk_test|whsec_|AKIA[0-9A-Z]{16}|-----BEGIN|api[_-]?key\s*[:=]\s*['\"][A-Za-z0-9])" convex src --glob '!**/_generated/**'
rg -n "process\.env\." convex src --glob '!**/_generated/**'

Secrets belong in Convex environment variables (npx convex env set NAME value), read through process.env in the action or HTTP action that makes the external call. A secret literal in source is critical. Anything read from process.env in client code (src/) is public; only non secret VITE_ or NEXT_PUBLIC_ values belong there. Confirm dev and prod deployments use different keys.

8. Write the report

Fill in references/audit-report-template.md. One finding per issue, ordered by severity, each with location, evidence, and a concrete fix. Include the data access matrix. Finish with the list of public functions reviewed and judged correctly anonymous, so the next auditor does not repeat that work.

Severity scale

SeverityMeaningExamples
CriticalAny anonymous caller can read or change other users' data, or a secret is exposedPublic mutation patches a document by client supplied ID with no ownership check; API key in source; webhook with no signature check
HighAn authenticated user can reach data or actions outside their scopeMissing org membership check in a multi tenant query; admin function reads role from client args
MediumDefense in depth gap with no direct exploit todayPublic function that should be internal; no rate limit on a costly action; upload URL with no auth
LowHygienev.any() on a non sensitive arg; missing return validator; .filter() where an index exists

Example finding

Severity: Critical
Location: convex/tasks.ts, updateTask (mutation, public)
Evidence: handler calls ctx.db.patch(args.taskId, { title: args.title }) after
  requireAuth(ctx) but never compares task.userId to the caller. Any signed in
  user can rename any task by guessing or capturing an ID.
Fix: load the task, compare task.userId to user._id, throw on mismatch. See
  references/authorization-patterns.md, "Ownership checks".
Verified: reproduced by calling updateTask with another user's task ID from the
  dashboard function runner.

Common mistakes

MistakeWhy it breaksDo this instead
Treating internalMutation as safe without tracing callersThe public function that schedules it may pass unverified IDsAudit the scheduling call site, not just the internal function
Checking auth only in the UIAnyone can call the function from the dashboard or a scriptEvery public handler checks identity itself
Comparing ownership to identity.emailEmails can be reused or unverified across providersCompare to user._id looked up via tokenIdentifier
Mixing return null and throw for the same caseLeaks record existence through response differencesIn queries, return null for both "not found" and "not yours"
Rate limiting only in the clientAttackers skip the clientUse @convex-dev/rate-limiter inside the mutation or action
Signing off after fixes without re running the grepsFixes often move the problemRe run steps 1 through 7 after remediation

Checklist

  • Every exported query, mutation, action is listed with its intended caller
  • Every function that should be internal is internal*
  • Every public function either checks identity or is documented as intentionally anonymous
  • Every table has a filled row in the data access matrix
  • Every http.ts route verifies its caller and validates its body
  • Upload URL generation and file URL reads are gated by ownership
  • No api.* reference inside scheduler, cron, or ctx.run* calls
  • No secret literals in source; dev and prod use different keys
  • Costly or abusable mutations and actions are rate limited
  • Report written with severity, location, evidence, and fix for each finding

Docs

© waynesutton, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references, assets) in skills/convex-security-audit of waynesutton/builder-skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/large-logo.png
  • assets/small-logo.svg
  • references/attack-surface.md
  • references/audit-report-template.md
  • references/authorization-patterns.md

Open the folder on GitHubat commit 82d1ce2

Compare with similar skills

Convex Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Convex Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Convex Security Audit this skillwaynesutton/builder-skills406—~2.6kAutomated safety check: PassApache-2.0
Fireauto Secure Guideimgompanda/fireauto140—~371Automated safety check: NotesMIT
API Security ReviewOWASP/secure-agent-playbook187—~744Automated safety check: PassCC-BY-4.0
Security Reviewaffaan-m/ECC276k1 repos~3.2kAutomated safety check: NotesMIT
Security Reviewtrycompai/comp2k—~853Automated safety check: PassAGPL-3.0
AWS Advisordiegosouzapw/awesome-omni-skills159—~4.3kAutomated safety check: PassMIT

Similar skills

  • Fireauto Secure Guide

    imgompanda/fireauto

    "보안 점검", "security check", "security audit", "취약점 분석", "vulnerability scan", "보안 감사", "시크릿 노출", "API 보안", "인증 점검", "rate limit" 등 보안 관련 코드 리뷰나 취약점 감사 시 사용하세요.

    140 GitHub stars~371 tokensUpdated 6 mo ago
    SecurityAuto-check: notes
  • API Security Review

    OWASP/secure-agent-playbook

    Comprehensive API security review against OWASP API Security Top 10 (2023).

    187 GitHub stars~744 tokensUpdated 14 days ago
    SecurityAuto-check passed
  • Security Review

    affaan-m/ECC

    Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın.

    276k GitHub starsUsed in 1 repo~3.2k tokens
    SecurityAuto-check: notes
  • Security Review

    trycompai/comp

    Check code for the most common, high-risk security vulnerabilities (broken access control, tenant isolation, injection, secrets, SSRF, auth/session, unsafe file handling, mass assignment) before it…

    2k GitHub stars~853 tokensUpdated 2 days ago
    SecurityAuto-check passed
  • AWS Advisor

    diegosouzapw/awesome-omni-skills

    AWS Advisor workflow skill. An agent skill from diegosouzapw/awesome-omni-skills.

    159 GitHub stars~4.3k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from waynesutton/builder-skills

All 17 skills in this repo
  • Convex Agents

    waynesutton/builder-skills

    Builds AI agents on the Convex agent component: threads, messages, tools that call queries and mutations, streaming, RAG with vector search, and workflows for multi step jobs.

    406 GitHub stars~2.2k tokensUpdated 11 days ago
    Auto-check passed
  • Convex Best Practices

    waynesutton/builder-skills

    Production patterns for Convex apps and the rules the @convex-dev/eslint-plugin enforces: validators, indexes, idempotent mutations, avoiding OCC conflicts, thin function wrappers, error handling.

    406 GitHub stars~2.6k tokensUpdated 11 days ago
    Auto-check passed
  • Convex Component Authoring

    waynesutton/builder-skills

    Creates reusable Convex components with defineComponent, a clean client wrapper, their own schema, and an npm publish setup.

    406 GitHub stars~2.6k tokensUpdated 11 days ago
    Auto-check passed
  • Convex Cron Jobs

    waynesutton/builder-skills

    Schedules work in Convex: cron jobs in convex/crons.ts, one off scheduled functions with runAfter and runAt, batching large jobs, and cancelling or inspecting the queue.

    406 GitHub stars~2k tokensUpdated 11 days ago
    Auto-check passed
  • Convex HTTP Actions

    waynesutton/builder-skills

    Adds HTTP endpoints in convex/http.ts: webhook receivers with signature checks, REST style routes, CORS, auth headers, streaming responses, and file uploads over HTTP.

    406 GitHub stars~2.6k tokensUpdated 11 days ago
    Auto-check passed
  • Convex Migrations

    waynesutton/builder-skills

    Changes a live Convex schema without downtime: make a field optional, backfill in batches, flip the validator, then clean up.

    406 GitHub stars~2.1k tokensUpdated 11 days ago
    Auto-check passed

Questions about Convex Security Audit

What does Convex Security Audit do?

Deep security review of a Convex app: authorization model, data access paths per table, HTTP action exposure, rate limiting, file storage access, scheduled function trust, and a written findings…. Convex Security Audit is an agent skill from waynesutton/builder-skills. Deep security review of a Convex app: authorization model, data access paths per table, HTTP action exposure, rate limiting, file storage access, scheduled function trust, and a written findings report.

When should I use Convex Security Audit?

Convex Security Audit fits situations like: asks for a full audit rather than a quick check; tasks that involve Security review; tasks that involve File uploads and storage.

How do I install Convex Security Audit in Claude Code?

Run `npx skills add waynesutton/builder-skills --skill convex-security-audit -a claude-code`. Or copy the skill folder (skills/convex-security-audit in waynesutton/builder-skills) into .claude/skills/convex-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Convex Security Audit in Codex?

Run `npx skills add waynesutton/builder-skills --skill convex-security-audit -a codex`. Or copy the skill folder (skills/convex-security-audit in waynesutton/builder-skills) into .agents/skills/convex-security-audit in your project. Codex loads it when a task matches its description.

Can I use Convex Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add waynesutton/builder-skills --skill convex-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/convex-security-audit, .gemini/skills/convex-security-audit, .github/skills/convex-security-audit and .opencode/skills/convex-security-audit in your project.

What does Convex Security Audit need to run?

Going by SKILL.md and its folder, Convex Security Audit needs the command-line tools its instructions call (rg and npx). Our summary lists: Node.js.

Does Convex Security Audit access the network?

SKILL.md names 1 domain. As links in the text: docs.convex.dev. This is read from the text; nothing was executed.

Is Convex Security Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Convex Security Audit use?

Convex Security Audit is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Convex Security Audit use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.8k tokens, read only when the agent opens those files.

What are the alternatives to Convex Security Audit?

Skills that share tags, products or a category with Convex Security Audit: Fireauto Secure Guide (imgompanda/fireauto, 140 stars), API Security Review (OWASP/secure-agent-playbook, 187 stars), Security Review (affaan-m/ECC, 276k stars) and Security Review (trycompai/comp, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Convex Security Audit?

waynesutton (a GitHub user) maintains it in waynesutton/builder-skills, which has 406 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on September 28, 2026.

Source: waynesutton/builder-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.