Curated library of 39 AI agent skills for Ruby on Rails development. Organized by category: planning, testing, code-quality, ddd, engines, infrastructure, api, patterns, context, orchestration, and workflows. Includes 5 callable workflow skills (rails-tdd-loop, rails-review-flow, rails-setup-flow, rails-quality-flow, rails-engines-flow) for complete development cycles. Covers code review, architecture, security, testing (RSpec), engines, service objects, DDD patterns, and TDD automation.
95
98%
Does it follow best practices?
Impact
95%
1.20xAverage score across 35 eval scenarios
Passed
No known issues
{
"context": "Tests whether the agent replaces presence-only authorization checks with proper Pundit policy objects, removes inline logic from controllers, covers all four roles in both policy and request specs, and uses policy_scope for index actions.",
"type": "weighted_checklist",
"checklist": [
{
"name": "Policy class replaces inline logic",
"description": "app/policies/project_policy.rb exists and contains authorization logic for update? and destroy? methods",
"max_score": 8
},
{
"name": "No presence-only checks remain",
"description": "The refactored controller does NOT contain `if current_user.present?` as the sole authorization gate for update or destroy actions",
"max_score": 10
},
{
"name": "authorize called in controller",
"description": "The update and destroy actions call `authorize @project` rather than performing any manual permission check",
"max_score": 10
},
{
"name": "Index uses policy_scope",
"description": "The index action uses `policy_scope(Project)` instead of `Project.all`",
"max_score": 8
},
{
"name": "Policy class inherits ApplicationPolicy",
"description": "ProjectPolicy inherits from ApplicationPolicy (not directly from Object or another base)",
"max_score": 6
},
{
"name": "Admin role permitted in policy",
"description": "The policy grants admin users permission to update? and destroy? any project",
"max_score": 8
},
{
"name": "Owner role permitted in policy",
"description": "The policy grants the project owner permission to update? and destroy? their own project",
"max_score": 8
},
{
"name": "Non-owner role denied in policy",
"description": "The policy denies update? and destroy? to an authenticated user who is not the owner and not an admin",
"max_score": 8
},
{
"name": "Guest role tested in specs",
"description": "The policy spec or request spec includes a case for a nil/unauthenticated user asserting denial of update or destroy",
"max_score": 8
},
{
"name": "permit_action matchers in policy spec",
"description": "The policy spec uses `permit_action` / `not_to permit_action` matchers to assert permissions",
"max_score": 8
},
{
"name": "Request spec covers multiple roles",
"description": "The request spec covers at least two distinct roles (e.g., owner vs non-owner) for a mutating action (PATCH/DELETE)",
"max_score": 8
},
{
"name": "implementation_notes identifies flaw",
"description": "implementation_notes.md identifies that presence-only checks (`current_user.present?`) were the core security flaw",
"max_score": 10
}
]
}docs
evals
scenario-1
scenario-2
scenario-3
scenario-4
scenario-5
scenario-6
scenario-7
scenario-8
scenario-9
scenario-10
scenario-11
scenario-12
scenario-13
scenario-14
scenario-15
scenario-16
scenario-17
scenario-18
scenario-19
scenario-20
scenario-21
scenario-22
scenario-23
scenario-24
scenario-25
scenario-26
scenario-27
scenario-28
scenario-29
scenario-30
scenario-31
scenario-32
scenario-33
scenario-34
scenario-35
mcp_server
skills
api
api-rest-collection
rails-graphql-best-practices
code-quality
rails-architecture-review
rails-code-conventions
rails-code-review
rails-review-response
rails-security-review
rails-stack-conventions
assets
snippets
refactor-safely
context
rails-context-engineering
rails-project-onboarding
ddd
ddd-boundaries-review
ddd-rails-modeling
ddd-ubiquitous-language
engines
rails-engine-compatibility
rails-engine-docs
rails-engine-extraction
rails-engine-installers
rails-engine-release
rails-engine-reviewer
rails-engine-testing
infrastructure
rails-api-versioning
rails-background-jobs
rails-database-seeding
rails-frontend-hotwire
rails-migration-safety
rails-performance-optimization
orchestration
rails-skills-orchestrator
patterns
ruby-service-objects
strategy-factory-null-calculator
yard-documentation
planning
create-prd
generate-tasks
ticket-planning
testing
rails-bug-triage
rails-tdd-slices
rspec-best-practices
rspec-service-testing