CtrlK
BlogDocsLog inGet started
Tessl Logo

igmarin/rails-agent-skills

Curated library of 28 public AI agent skills for Ruby on Rails development. Organized by category: testing, code-quality, engines, infrastructure, api, and context. Covers code review, architecture, security, testing (RSpec), engines, Hotwire, and TDD automation. Shared Ruby skills (YARD docs, DDD, service objects) have moved to ruby-core-skills. Repository agents remain documented in GitHub but are intentionally excluded from the Tessl tile.

93

1.78x
Quality

95%

Does it follow best practices?

Impact

93%

1.78x

Average score across 28 eval scenarios

SecuritybySnyk

Passed

No known issues

Overview
Quality
Evals
Security
Files

PITFALLS.mdskills/code-quality/security-check/

Rails Security Review — Pitfalls

PitfallReality
"Only internal users access this"Internal tools get compromised — apply the same standards
permit! "just for now"It will ship. Allowlist from day one
"Rails handles CSRF automatically"Only if protect_from_forgery is active and tokens are verified
String interpolation in SQLSQL injection — always use parameterized queries
html_safe on user contentXSS — only call on developer-controlled strings
Secrets in committed filesUse encrypted credentials. Rotate immediately if exposed
No authorization before destructive actionsAlways check permissions, even for internal routes
Background job inputs not validatedJobs are entry points — validate inputs like a controller

skills

README.md

tile.json