convex-auth
Add Convex Authentication to Your App
Convex authentication can fail silently when server and client configuration diverge. This skill wires providers, keys, configuration, UI, and verification steps.
Vor der Installation anhalten und eine Bestätigung anfordern.
Prüfen Sie den Plan und holen Sie vor Änderungen an Dateien die ausdrückliche Zustimmung des Benutzers ein.
Mit meinem Agent installieren
Kopieren Sie diese Anfrage in Ihren Agent. Sie enthält die maßgebliche Skill-Seite und das Manifest.
Review the Skillstore skill "convex-auth" from https://skillstore.io/skills/get-convex-convex-auth.md and its manifest at https://skillstore.io/api/skills/get-convex-convex-auth/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Ihr Agent sollte weiterhin seinen Plan anzeigen und alle von der Sicherheitsrichtlinie verlangten Bestätigungen anfordern.
Agent-lesbare Ressourcen
Verwenden Sie diese Links, wenn ein KI-Agent, Crawler oder Skript sauberen Kontext benötigt, statt die vollständige Seite zu lesen.
Testen
„convex-auth“ wird verwendet. Add passkey authentication to this Convex application.
Erwartetes Ergebnis:
Passkey authentication is configured on the server and client. Required deployment variables are set, protected routes are wired, and sign-in is verified.
„convex-auth“ wird verwendet. Why does this application remain signed out after login?
Erwartetes Ergebnis:
The audit identifies a missing or incorrect auth.config.ts entry, updates provider wiring, and confirms that authenticated state now persists.
„convex-auth“ wird verwendet. Switch this application from passkeys to Google OAuth.
Erwartetes Ergebnis:
The provider configuration now uses Google OAuth. Existing client components are preserved, required credentials are listed, and the sign-in flow is tested.
Sicherheitsaudit
Hohes RisikoEight findings are confirmed because package execution and JWT secret handling create project, supply-chain, and credential-exposure risks. Six findings are false positives caused by Markdown, a fixed import, an illustrative localhost URL, or misclassified prose. No prompt injection or malicious intent was found.
Bestätigte Sicherheitsbedenken (1)
Elemente der Fähigkeitsprüfung (7)
Dies sind echte lokale Fähigkeiten, die für diese Fähigkeit erwartet werden können; daher müssen sie überprüft werden, werden jedoch nicht als bestätigtes bösartiges Verhalten gezählt.
Risikofaktoren
⚡ Enthält Skripte (1)
⚙️ Externe Befehle (6)
🌐 Netzwerkzugriff (1)
🔑 Umgebungsvariablen (4)
Diesen Bericht teilen & zitieren
Teile den versionierten Bewertungsbericht, das neutrale Badge, die Einbettungskarte und Zitate. Skillstore berichtet Nachweise, ohne zu entscheiden, ob dieser Skill sicher ist.
Berichtslink kopieren
https://skillstore.io/skills/get-convex-convex-auth/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown-Badge
[](https://skillstore.io/skills/get-convex-convex-auth?utm_source=security_passport_badge)HTML-Badge
<a href="https://skillstore.io/skills/get-convex-convex-auth?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/get-convex-convex-auth/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Einbettungskarte
<iframe src="https://skillstore.io/embed/skills/get-convex-convex-auth.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Wissenschaftliche Zitate (APA · BibTeX · CFF)
APA-Zitat
get-convex. (2026). convex-auth security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/get-convex-convex-auth/audits/1BibTeX-Zitat
@techreport{get-convex-get-convex-convex-auth-2026,
author = {get-convex},
title = {convex-auth security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/get-convex-convex-auth/audits/1},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "convex-auth security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "get-convex"
date-released: "2026-09-07"
url: "https://skillstore.io/skills/get-convex-convex-auth/audits/1"
identifiers:
- type: other
value: "skillstore:get-convex-convex-auth:audit:1"
description: "Skillstore immutable audit report identifier"
Skillstore-Score
Warum dieser Score Evidenzvertrauen: MittelWas Sie erstellen können
Add passkeys to a prototype
Configure passkey sign-in across the Convex server and application client, then verify the complete flow.
Integrate an OAuth provider
Add requested OAuth authentication while preserving the existing Convex application structure and route behavior.
Repair silent sign-out failures
Inspect provider wiring and auth.config.ts, then correct configuration that prevents authenticated sessions.
Diese Prompts ausprobieren
Add passkey sign-in to my current Convex app. Configure the server, client provider, sign-in UI, route guards, and verification.
Configure Google OAuth for this Convex app. Reuse existing UI patterns, identify required credentials, and verify successful sign-in and sign-out.
Audit this Convex authentication setup. Find configuration mismatches, missing client wiring, unsafe key handling, and incomplete route protection.
Migrate this app to Convex Auth with minimal disruption. Preserve user flows, document credential changes, and validate protected routes end to end.
Bewährte Praktiken
- Use passkeys unless product requirements explicitly require password or OAuth authentication.
- Store signing keys only in approved secret systems and remove temporary local key files immediately.
- Verify sign-in, sign-out, session persistence, and protected route behavior before completion.
Vermeiden
- Do not omit auth.config.ts because failures can appear as persistent anonymous sessions.
- Do not pass private keys through visible command arguments or commit generated key files.
- Do not import missing UI primitives or execute unpinned package versions.
Häufig gestellte Fragen
Which authentication method is the default?
Does this skill create OAuth credentials?
Why is auth.config.ts required?
How are JWT signing keys generated?
Can this run in a headless environment?
What must be verified before completion?
Entwicklerdetails
Autor
get-convexLizenz
MIT
Skillstore-Revision
r1
Versionshinweis
Der Autor hat keine Version angegeben.
Ref.
d9e5ab86dafd32a1ddde9b8b4fde177589b55b95
Aktualität der Wartung
8.9.2026
Nutzung
1 Downloads · 0 Aufrufe
Dateistruktur
📄 SKILL.md