Skip to content
Back to skills

Ruby Rails Patterns

ASecurity

Ruby 3.3+ / Rails 7-8 discipline — Sandi Metz rules (classes ≤ 100 LOC, methods ≤ 5 LOC, ≤ 4 args), frozen_string_literal mandatory, RuboCop at strict (cyclomatic ≤ 7, AbcSize ≤ 15), modern Ruby idioms (endless methods, pattern matching, hash shorthand, numbered block params), service objects + form objects + query objects + value objects, Rails 8 Solid Queue / Solid Cache / Solid Cable defaults, no monkey-patching outside Refinements / Module#prepend, Brakeman + bundler-audit + RSpec at stri...

  • 12 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 6, 2026
ai-agentsrubynoderailstestingsecurity

Security analysis

A100/100

Pro scans all 7 files and shows the line behind each finding

Scanned October 6, 2026

npx -y skills add Nmor/the-council --skill ruby-rails-patterns --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Ruby Rails Patterns?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Ruby Rails Patterns
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/nmor-ruby-rails-patterns-the-council/badge)](https://www.skillsdirectory.com/skills/nmor-ruby-rails-patterns-the-council)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: ruby-rails-patterns
description: Ruby 3.3+ / Rails 7-8 discipline — Sandi Metz rules (classes ≤ 100 LOC, methods ≤ 5 LOC, ≤ 4 args), frozen_string_literal mandatory, RuboCop at strict (cyclomatic ≤ 7, AbcSize ≤ 15), modern Ruby idioms (endless methods, pattern matching, hash shorthand, numbered block params), service objects + form objects + query objects + value objects, Rails 8 Solid Queue / Solid Cache / Solid Cable defaults, no monkey-patching outside Refinements / Module#prepend, Brakeman + bundler-audit + RSpec at strict. Select explicitly when this guidance applies.
paths:
  - "**/*.rb"
  - "**/*.rake"
  - "**/*.gemspec"
  - "**/Gemfile"
  - "**/Gemfile.lock"
  - "**/Rakefile"
  - "**/config.ru"
  - "**/.rspec"
  - "**/spec/**/*.rb"
disable-model-invocation: true
---

# ruby-rails-patterns

> **Size budget: 25 KB.** Check: wc -c. Gate: node ~/.claude/scripts/token-budget.mjs --check
>
> Migrated 2026-06-02 from `~/.claude/rules-library/ruby/` as part of the lazy-rules-loading plan.
> Phase H will delete the source files.

## Purpose

Ruby 3.3+ / Rails 7-8 discipline for production code: small classes and methods per Sandi
Metz, frozen string literals, RuboCop at a strict baseline, the four Rails object patterns
(service / form / query / value), OWASP-mapped Rails security, and RSpec at strict. The
bodies below were migrated from `~/.claude/rules-library/ruby/`.

## Routing table

This skill uses progressive disclosure: the detail lives in `references/`, one concern per
file. Read the row you need — not the whole set.

| Topic | Read |
| --- | --- |
| Coding style — naming, Sandi Metz rules, frozen string literals, modern Ruby idioms (endless methods, pattern matching, hash shorthand, numbered block params), class structure, modules + mixins, Rails-specific style, strict `.rubocop.yml` | [`references/coding-style.md`](references/coding-style.md) |
| Hooks + CI — pre-commit gates on staged Ruby files, Rails initializer hooks (security headers, parameter filtering), the CI workflow | [`references/hooks.md`](references/hooks.md) |
| No-discards (Ruby) — the fifteen banned patterns (bare `rescue`, `rescue nil`, `send` with user input, `eval`, suppressions, unsynchronised `Hash#[]=`, `puts`, `Time.now`, deep `ENV`, monkey-patching, unordered `find_each`, `update_columns`, `for ... in`, discarded multiple assignment), required tooling, verification block | [`references/no-discards.md`](references/no-discards.md) |
| Rails object patterns — service objects, form objects, query objects, value objects, concerns vs inheritance, ActiveRecord pitfalls, reuse-first | [`references/patterns.md`](references/patterns.md) |
| Security — OWASP Top 10 mapped to Rails (A01-A10), CSRF + strong parameters, secrets, required security tooling | [`references/security.md`](references/security.md) |
| Testing — Rails test pyramid, RSpec idioms, FactoryBot, WebMock + VCR, Capybara + Cuprite system tests, the ten hard rules | [`references/testing.md`](references/testing.md) |

Files in this skill

  • SKILL.md3 KB
  • references/coding-style.md4.8 KB
  • references/hooks.md2.3 KB
  • references/no-discards.md6.5 KB
  • references/patterns.md5.5 KB
  • references/security.md5 KB
  • references/testing.md6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…