# Convex Verify > Demuestra que una feature de Convex funciona: seedea datos, la ejecuta como varios usuarios simulados vía convex-test y afirma el comportamiento, incluidos los casos negativos de autorización. Fuente: https://skillsagentes.com/skills/get-convex/agent-skills/convex-verify Markdown: https://skillsagentes.com/skills/get-convex/agent-skills/convex-verify.md Repositorio: https://github.com/get-convex/agent-skills Autor: get-convex Licencia: Apache-2.0 Actualizado: el mes pasado Coste de contexto: 45 tok instalada, 1.2k tok al activarse, 1.2k tok con todos los archivos del bundle Bundle: 1 archivo, 5 KB Permisos que pide: ninguno declarado ## Instalación Un skill son archivos markdown: los mismos archivos valen para cualquier agente y lo único que cambia es el directorio de destino, es decir la bandera `--agent`. Añade `-g` para instalarlo en todos los proyectos de la máquina. ```bash # Claude Code npx -y skills add get-convex/agent-skills --skill convex-verify --agent claude-code # Cursor npx -y skills add get-convex/agent-skills --skill convex-verify --agent cursor # Codex npx -y skills add get-convex/agent-skills --skill convex-verify --agent codex # Gemini CLI npx -y skills add get-convex/agent-skills --skill convex-verify --agent gemini # Windsurf npx -y skills add get-convex/agent-skills --skill convex-verify --agent windsurf # Cline npx -y skills add get-convex/agent-skills --skill convex-verify --agent cline ``` ## Qué hace - Seeda datos realistas usando las propias funciones de la app más fixtures directos vía t.run - Ejecuta la función objetivo como owner, otro usuario autenticado y usuario no autenticado con t.withIdentity - Afirma casos positivos y, sobre todo, negativos (llamador equivocado rechazado, data-scope respetado) - Configura vitest.config.ts con environment 'edge-runtime' y convex-test inlined si falta - Emite un finding en el bus (authz/correctness) para cualquier aserción fallida, con la llamada exacta ## Cuándo usarla - El usuario acaba de construir o cambiar una query/mutation/action de Convex y quiere probarla - Se necesita comprobar que un no-owner es realmente rechazado, no solo que el código compila - Se requiere validar que una lista/query devuelve solo las filas del caller y no las de otro usuario ## Cuándo no - La petición es configurar un framework de test en general, no probar una feature concreta (eso es la capability `test`) ## Qué la activa - "Verifica que esta mutation de Convex rechaza a usuarios que no son el owner" - "Prueba con convex-test que mi query de listado solo devuelve las filas del usuario actual" - "Demuestra que esta acción falla para un caller no autenticado" ## Antes de instalar - Requiere convex-test y vitest como dev deps, @edge-runtime/vm instalado, y un vitest.config.ts con test.environment: 'edge-runtime' y server.deps.inline: ['convex-test']. ## Archivos - SKILL.md — 5 KB ## SKILL.md Reproducido tal cual desde get-convex/agent-skills bajo Apache-2.0. Esta sección es el documento original y está en inglés. # Prove a feature works — seed, drive, assert A green typecheck proves the code parses; it does not prove a non-owner is actually denied, that a query returns the right rows, or that a mutation has the effect it claims. This capability closes that gap with the loop the whole field is missing: seed → drive → assert, run in-process with `convex-test` so it needs no deployment. Its highest-value assertions are the NEGATIVE ones — the caller who should be refused — because those are exactly the authz defects the 30-app corpus shows are the #1 real bug and the ones a happy-path demo never catches. ## Workflow 1. IDENTIFY the feature to prove: the specific exported query/mutation/action (or a small set) the user just built/changed, and its intended behavior — who should be allowed, what data should come back, what a mutation should change. If the intent is unstated, ask one focused question rather than guessing the contract. 2. SET UP `convex-test`: ensure `convex-test` + `vitest` are dev deps AND a `vitest.config.ts` sets `test.environment: "edge-runtime"` with `server.deps.inline: ["convex-test"]` — WITHOUT that config, `convexTest(schema)` fails at runtime with `import.meta.glob is not a function` (verified). Also install `@edge-runtime/vm`. Then `convexTest(schema)` gives a `t` handle. Reuse the project's existing test setup if present (compose with the `test` capability, don't fork it). 3. SEED realistic data through the app's OWN functions where possible (so the seed exercises the same validators/mutations a real user would), falling back to `t.run(async (ctx) => ctx.db.insert(...))` for fixtures the public API can't create. Seed at least: the caller's own rows AND a second user's rows, so cross-user access is testable. 4. DRIVE the feature as DIFFERENT identities with `t.withIdentity({ subject, tokenIdentifier, ... })`: call the function as (a) the legitimate owner, (b) a different authenticated user, and (c) unauthenticated (`t` with no identity). Use the real identity shape the app's auth uses (subject/tokenIdentifier), matching how ownership is resolved. 5. ASSERT behavior — POSITIVE and NEGATIVE: - positive: the owner gets the expected rows / the mutation made the expected change (`expect(await t.withIdentity(owner).query(api.x.y, args)).toEqual(...)`). - NEGATIVE (the load-bearing half): a different user calling the same function is REFUSED — `await expect(t.withIdentity(other).mutation(api.x.cancel, {id})).rejects.toThrow(/forbidden|not authorized|403/)` — and an unauthenticated caller is refused where auth is required. A feature is not proven until the wrong caller is shown to be blocked. - data-scope: a list/query returns ONLY the caller's rows, never the second user's (assert the second user's row is absent). 6. RUN the tests (`npx vitest run`) and report: what was proven (each positive + negative assertion that passed), and — critically — any assertion that FAILED, because a failed negative assertion is a real authz hole found before ship. Emit findings on the bus (specs/finding.schema.json, class authz/correctness, evidence kind probe-result with the exact failing call) for anything that didn't behave. 7. Do NOT weaken a test to make it pass: if the owner-only query returns another user's row, the FIX is in the function (hand to convex-authz), not in the assertion. A test changed until it's green proves nothing. ## Rules - Prove behavior, not compilation: every verification includes at least one NEGATIVE assertion (a caller who should be refused is refused) — the happy path alone is not proof. - Drive the feature as multiple identities with t.withIdentity (owner, other user, unauthenticated) using the app's real subject/tokenIdentifier shape. - Seed both the caller's rows AND a second user's rows so cross-user access and data-scope are actually testable. - A vitest.config.ts with environment 'edge-runtime' + convex-test inlined is REQUIRED for convex-test to run (import.meta.glob needs it); author it, don't just author the test file. - Run in-process with convex-test — no deployment needed; compose with the `test` capability's setup rather than forking it. - Never weaken an assertion to make it pass: a failing negative test is a real defect → hand the fix to convex-authz/convex-expert, don't edit the test until it's green. - Emit a bus finding for any assertion that failed (authz/correctness, evidence: the failing probe call) so a composite pass or self-heal can pick it up. - This drives a SPECIFIC built feature; a request to set up a test framework generally is the `test` capability. ## Dónde encaja - Categoría: [Testing y QA](https://skillsagentes.com/categorias/testing-qa.md) — Flujos de testing unitario, de integración y end-to-end. - Creador: [get-convex](https://skillsagentes.com/creators/get-convex.md) — 33 skills en el directorio - [Todas las skills](https://skillsagentes.com/skills.md) - [Ranking de instalaciones](https://skillsagentes.com/ranking.md) ## Otras skills del mismo repositorio - [Convex Quickstart](https://skillsagentes.com/skills/get-convex/agent-skills/convex-quickstart.md): Levanta un template Next.js + Convex barebones a partir de una idea en una frase. - [Convex Design](https://skillsagentes.com/skills/get-convex/agent-skills/convex-design.md): Diseña y construye backends reactivos y type-safe de nivel producción en Convex: schema, queries/mutations/actions, índices, auth, storage, scheduling, multiplayer en tiempo real y workflows LLM/agentes. - [Convex Authz](https://skillsagentes.com/skills/get-convex/agent-skills/convex-authz.md): Audita y refuerza la autorización de una app Convex: impersonación por identity-from-arg, checks de ownership por documento faltantes, queries públicas que filtran datos por un id del cliente y escrituras en un contenedor ajeno. - [Convex Expert](https://skillsagentes.com/skills/get-convex/agent-skills/convex-expert.md): Especialista en el backend de Convex: código dentro de convex/ (funciones, schemas, índices, queries, mutations, actions, endpoints HTTP, cron jobs, storage, auth y componentes). - [Convex Agent](https://skillsagentes.com/skills/get-convex/agent-skills/convex-agent.md): Añade un backend de agente de IA / RAG (@convex-dev/agent) a la app Convex. --- Skills Agentes · [Índice de páginas en markdown](https://skillsagentes.com/sitemap.md) · [Inicio](https://skillsagentes.com/index.md)