CtrlK
BlogDocsLog inGet started
Tessl Logo

igmarin/rails-agent-skills

Curated library of AI agent skills for Ruby on Rails development. Covers code review, architecture, security, testing (RSpec), engines, service objects, DDD patterns, and workflow automation.

98

1.38x
Quality

99%

Does it follow best practices?

Impact

98%

1.38x

Average score across 26 eval scenarios

SecuritybySnyk

Passed

No known issues

Overview
Quality
Evals
Security
Files

PITFALLS.mdrails-security-review/

Rails Security Review — Pitfalls

PitfallReality
"Only internal users access this"Internal tools get compromised — apply the same standards
permit! "just for now"It will ship. Whitelist from day one
"Rails handles CSRF automatically"Only if protect_from_forgery is active and tokens are verified
String interpolation in SQLSQL injection — always use parameterized queries
html_safe on user contentXSS — only call on developer-controlled strings
Secrets in committed filesUse encrypted credentials. Rotate immediately if exposed
No authorization before destructive actionsAlways check permissions, even for internal routes
Background job inputs not validatedJobs are entry points — validate inputs like a controller

rails-security-review

README.md

tile.json