Comprehensive Ruby on Rails application audit skill for Claude Code.
This skill performs a thorough audit of your Rails application covering:
- Coding Standards: Ruby and Rails best practices
- Testing & Coverage: Test quality and coverage analysis
- Security: OWASP Top 10 vulnerabilities and Rails-specific security issues
- Architecture: Code organization, design patterns, and maintainability
- Performance: Database queries, caching, and optimization opportunities
/rails-auditThis will generate a report with default filename: rails-audit-report-YYYY-MM-DD.md
/rails-audit my-custom-reportThis will generate: my-custom-report.md and my-custom-report.pdf
The skill generates two files:
- Markdown Deck: A presentation-style markdown file with slides
- PDF: Converted PDF version of the deck (requires dependencies)
The audit report includes:
- Executive Summary: Overall health score and critical issues
- Audit Scope: Files analyzed, LOC, components
- Coding Standards: Style violations and anti-patterns
- Testing & Coverage: Coverage metrics and gaps
- Security Assessment: Vulnerabilities by severity
- Architecture Review: Strengths and improvements
- Performance Analysis: Bottlenecks and optimization opportunities
- Detailed Findings: Critical issues with file references
- Prioritized Recommendations: Immediate, short-term, and long-term actions
- Conclusion: Overall assessment and next steps
The skill will attempt to use one of the following tools for PDF conversion:
npm install -g @marp-team/marp-cli# macOS
brew install pandoc
# Linux
sudo apt-get install pandoc texlivenpm install -g mdpdfpip install grip
brew install wkhtmltopdf # macOSNote: If no PDF converter is available, the skill will still generate the markdown report.
- All
.rbfiles inapp/,lib/,config/ - Test files in
spec/ortest/ - Configuration files:
Gemfile,config/**/*.yml,config/**/*.rb - Database migrations:
db/migrate/
vendor/node_modules/tmp/log/- Any paths listed in
.gitignore
Based on:
- Ruby Style Guide
- Rails Style Guide
- Community best practices from major companies
Based on:
- OWASP Top 10
- Rails Security Guide
- Brakeman checks
Based on:
- RSpec best practices
- Rails testing guide
- Minimum 80% coverage recommendation
# Rails Application Audit Report
Project: MyRailsApp
Date: 2024-02-12
Ruby: 3.2.0
Rails: 7.1.0
---
# Executive Summary
Overall Score: 72/100
- Critical Issues: 3
- High Priority: 12
- Medium Priority: 28
- Low Priority: 15
---
# Security Assessment
## Vulnerabilities Found
- Critical: 2
- High: 5
- Medium: 8
- Low: 3
## Top Security Issues
1. SQL Injection in app/models/user.rb:45
2. Missing authorization check in app/controllers/posts_controller.rb:23
3. Hardcoded API key in config/initializers/external_api.rb:5
...- Run Before Major Releases: Use this audit before deploying to production
- Regular Audits: Run monthly or quarterly to catch technical debt
- Team Reviews: Share the PDF with your team for prioritization
- Track Progress: Run periodically and compare scores over time
- Focus on Critical First: Address critical and high-priority issues immediately
To customize the audit criteria, edit:
SKILL.md: Main audit workflowcoding-standards-reference.md: Coding standards to checksecurity-checklist.md: Security vulnerabilities to scan
You can use this skill as part of your CI/CD pipeline:
# Example: Run audit and fail if critical issues found
claude /rails-audit
# Parse output and check for critical issues- Install one of the PDF converters listed above
- The markdown report will still be available
- Check that .gitignore is properly configured
- Ensure Claude Code has read access to your project
- Check .gitignore to exclude vendor/, node_modules/
- Large projects (>100k LOC) may take several minutes
For issues or improvements:
- Check Claude Code documentation:
/help - Report issues: https://github.com/anthropics/claude-code/issues
Current Version: 1.0.0 Last Updated: 2024-02-12