rails-audit-thoughtbot — security grade SAFE, quality 73/100

Security audit verdict: SAFE · quality 73/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by thoughtbot · Claude Skill · ★ 239

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is rails-audit-thoughtbot safe to install? View the security audit →

About rails-audit-thoughtbot

Rails Audit Skill (thoughtbot Best Practices) A [Claude Code][claude-code] skill that performs comprehensive code audits of Ruby on Rails applications based on [thoughtbot's][thoughtbot] Ruby Science and Testing Rails best practices. [claude-code]: https://docs.anthropic.com/en/docs/claude-code [thoughtbot]: https://thoughtbot.com Quick links [Ruby Science][ruby-science] - thoughtbot's guide to fixing code smells [Testing Rails][testing-rails] - thoughtbot's guide to testing Rails applications [Rails Antipatterns][rails-antipatterns] - Best practices for Ruby on Rails refactoring (Chad Pytel & Tammer Saleh) [ruby-science]: https://github.com/thoughtbot/ruby-science [testing-rails]: https://github.com/thoughtbot/testing-rails [rails-antipatterns]: https://www.informit.com/store/rails-antipatterns-best-practice-ruby-on-rails-refactoring-9780321604811 Table of contents Overview Installation Usage Full application audit Targeted audit Optional data collection SimpleCov (test coverage) RubyCritic (code quality) Reference materials Contributing License About thoughtbot Overview This skill analyses Rails applications and generates detailed audit reports covering: Test

aiai-agentsartificial-intelligenceclauderailsruby-on-rails

Quick Facts

Stars239
Forks13
CategoryClaude Skill
LicenseMIT
Quality Score72.7527323199039/100
Open Issues1
Last Updated2026-08-21
Created2026-01-09
Platformsclaude-code
Est. Tokens~5k

rails-audit-thoughtbot alternative? Top 6 similar tools

Looking for a rails-audit-thoughtbot alternative? If you're comparing rails-audit-thoughtbot with other claude skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • c4-genai-suite by codecentric · ⭐ 173

    c4 GenAI Suite

  • atlassian-mcp-server by atlassian · ⭐ 1.1k

    Official remote MCP server for Atlassian. Securely connect Jira, Confluence, Jira Service Management, Bitbucke

  • DeepMCPAgent by cryxnet · ⭐ 806

    Model-agnostic plug-n-play LangChain/LangGraph agents powered entirely by MCP tools over HTTP/SSE.

  • deepcontext-mcp by Wildcard-Official · ⭐ 278

    DeepContext is an MCP server that adds symbol-aware semantic search to Claude Code, Codex CLI, and other agent

  • claudepro-directory by JSONbored · ⭐ 217

    HeyClaude (formerly Claude Pro Directory) is a searchable collection of pre-built AI skills, agents, MCP serve

  • os-ai-computer-use by 777genius · ⭐ 176

    AI controls your OS. OS AI Computer Use, OS and API agnostic. For now on OpenAI and Anthropic API. Desktop app

More Claude Skill Tools

Explore other popular claude skill tools:

View all Claude Skill tools →

Frequently Asked Questions

What is rails-audit-thoughtbot?

rails-audit-thoughtbot is Claude skill to run code audits. It is categorized as a Claude Skill with 239 GitHub stars.

How do I install or use rails-audit-thoughtbot?

You can find installation instructions and usage details in the rails-audit-thoughtbot GitHub repository at github.com/thoughtbot/rails-audit-thoughtbot. The project has 239 stars and 13 forks, indicating an active community.

What license does rails-audit-thoughtbot use?

rails-audit-thoughtbot is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to rails-audit-thoughtbot?

The top alternatives to rails-audit-thoughtbot on Agent Skills Hub include c4-genai-suite, atlassian-mcp-server, DeepMCPAgent. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Claude Skill tools