Skip to content

About

Comprehensive Ruby on Rails application audit skill for Claude Code. Covers coding standards, security (OWASP Top 10), testing, architecture, and performance. Generates detailed Markdown/PDF reports.

Resources

Stars

0 stars

Watchers

0 watching

Forks

 
 

Repository files navigation

Rails Audit Skill

Comprehensive Ruby on Rails application audit skill for Claude Code.

Overview

This skill performs a thorough audit of your Rails application covering:

  • Coding Standards: Ruby and Rails best practices
  • Testing & Coverage: Test quality and coverage analysis
  • Security: OWASP Top 10 vulnerabilities and Rails-specific security issues
  • Architecture: Code organization, design patterns, and maintainability
  • Performance: Database queries, caching, and optimization opportunities

Usage

Basic Usage

/rails-audit

This will generate a report with default filename: rails-audit-report-YYYY-MM-DD.md

Custom Filename

/rails-audit my-custom-report

This will generate: my-custom-report.md and my-custom-report.pdf

Output

The skill generates two files:

  1. Markdown Deck: A presentation-style markdown file with slides
  2. PDF: Converted PDF version of the deck (requires dependencies)

Report Structure

The audit report includes:

  1. Executive Summary: Overall health score and critical issues
  2. Audit Scope: Files analyzed, LOC, components
  3. Coding Standards: Style violations and anti-patterns
  4. Testing & Coverage: Coverage metrics and gaps
  5. Security Assessment: Vulnerabilities by severity
  6. Architecture Review: Strengths and improvements
  7. Performance Analysis: Bottlenecks and optimization opportunities
  8. Detailed Findings: Critical issues with file references
  9. Prioritized Recommendations: Immediate, short-term, and long-term actions
  10. Conclusion: Overall assessment and next steps

Dependencies for PDF Generation

The skill will attempt to use one of the following tools for PDF conversion:

Option 1: Marp (Recommended)

npm install -g @marp-team/marp-cli

Option 2: Pandoc

# macOS
brew install pandoc

# Linux
sudo apt-get install pandoc texlive

Option 3: mdpdf

npm install -g mdpdf

Option 4: Grip + wkhtmltopdf

pip install grip
brew install wkhtmltopdf  # macOS

Note: If no PDF converter is available, the skill will still generate the markdown report.

What Gets Audited

Files Included

  • All .rb files in app/, lib/, config/
  • Test files in spec/ or test/
  • Configuration files: Gemfile, config/**/*.yml, config/**/*.rb
  • Database migrations: db/migrate/

Files Excluded (respects .gitignore)

  • vendor/
  • node_modules/
  • tmp/
  • log/
  • Any paths listed in .gitignore

Audit Criteria

Coding Standards

Based on:

Security Standards

Based on:

  • OWASP Top 10
  • Rails Security Guide
  • Brakeman checks

Testing Standards

Based on:

  • RSpec best practices
  • Rails testing guide
  • Minimum 80% coverage recommendation

Example Output

# Rails Application Audit Report

Project: MyRailsApp
Date: 2024-02-12
Ruby: 3.2.0
Rails: 7.1.0

---

# Executive Summary

Overall Score: 72/100

- Critical Issues: 3
- High Priority: 12
- Medium Priority: 28
- Low Priority: 15

---

# Security Assessment

## Vulnerabilities Found
- Critical: 2
- High: 5
- Medium: 8
- Low: 3

## Top Security Issues
1. SQL Injection in app/models/user.rb:45
2. Missing authorization check in app/controllers/posts_controller.rb:23
3. Hardcoded API key in config/initializers/external_api.rb:5

...

Tips

  1. Run Before Major Releases: Use this audit before deploying to production
  2. Regular Audits: Run monthly or quarterly to catch technical debt
  3. Team Reviews: Share the PDF with your team for prioritization
  4. Track Progress: Run periodically and compare scores over time
  5. Focus on Critical First: Address critical and high-priority issues immediately

Customization

To customize the audit criteria, edit:

  • SKILL.md: Main audit workflow
  • coding-standards-reference.md: Coding standards to check
  • security-checklist.md: Security vulnerabilities to scan

Integration with CI/CD

You can use this skill as part of your CI/CD pipeline:

# Example: Run audit and fail if critical issues found
claude /rails-audit
# Parse output and check for critical issues

Troubleshooting

"PDF generation failed"

  • Install one of the PDF converters listed above
  • The markdown report will still be available

"Permission denied" errors

  • Check that .gitignore is properly configured
  • Ensure Claude Code has read access to your project

Audit takes too long

  • Check .gitignore to exclude vendor/, node_modules/
  • Large projects (>100k LOC) may take several minutes

Support

For issues or improvements:

Version

Current Version: 1.0.0 Last Updated: 2024-02-12

About

Comprehensive Ruby on Rails application audit skill for Claude Code. Covers coding standards, security (OWASP Top 10), testing, architecture, and performance. Generates detailed Markdown/PDF reports.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages