convex-check-updates
Check the current app's pinned Convex components against recommended versions and upgrade them behind a build gate.
How do I install this agent skill?
npx skills add https://github.com/get-convex/agent-skills --skill convex-check-updatesIs this agent skill safe to install?
- Gen Agent Trust Hubfail
This skill downloads and executes a script from an untrusted web address (graceful-tiger-715.convex.site). This action is highly dangerous because it allows the remote site to run any code it wants on your computer. Additionally, the skill runs further commands specified by that remote script, which could lead to theft of data or full system access.
- Socketwarn
1 alert: gptSecurity
- Snykfail
Risk: CRITICAL · 2 issues
What does this agent skill do?
check-updates
Detect stale Convex components in the current app against the anteater registry and, with explicit user consent, upgrade them one at a time behind a build gate (typecheck + next build). Each upgrade is gated and smoke-tested before the next.
Workflow
- Run
curl -fsSL https://graceful-tiger-715.convex.site/check-updates.mjs -o /tmp/cu.mjs && node /tmp/cu.mjsfrom the project root. - If COMPONENTS_UP_TO_DATE: tell the user; done.
- If COMPONENTS_STALE=<n>: list each stale entry (component name, installed → current, summary, breaking flag) and ask the user before touching anything.
- On yes: install the new ref, apply each migration.steps change (delegate convex/ edits to convex-expert), run every migration.gate command.
- If any gate command fails: revert (git checkout -- . or reinstall old ref) and report; never leave the app half-migrated.
- Give the user the smoke check (migration.smoke) to run after each successful upgrade.
- Repeat for each stale component, one at a time.
Rules
- Never upgrade without an explicit user yes — not even a minor version.
- Gate each component individually before moving to the next.
- breaking:true upgrades require a snapshot (commit or branch) before applying.
- Do not auto-republish a live *.convex.app site after upgrading without user confirmation.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/get-convex/agent-skills/convex-check-updates">View convex-check-updates on skillZs</a>