mirror of
https://github.com/alirezarezvani/claude-skills.git
synced 2026-10-10 03:27:56 +00:00
Adds 6 new language files to the code-reviewer skill, expanding coverage from 7 to 13 languages. Each file follows the established hybrid structure — language-specific rules inline, universal rules in rules/universal.md. Files added: - languages/c.md — memory safety, banned functions, pointer ownership, buffer bounds, UB - languages/cpp.md — smart pointers, RAII, reinterpret_cast, virtual destructors, C++17/20 - languages/rust.md — unsafe blocks, .unwrap() in production, Tokio pitfalls, clippy - languages/ruby.md — Rails-aware N+1, strong_parameters, YAML.safe_load, Marshal.load - languages/php.md — SQLi, unserialize, eval, file inclusion, CSRF, XSS, PHP 8.x - languages/dart.md — Dart + Flutter: dispose(), BuildContext across async, const widgets SKILL.md dispatch table and --language valid values updated accordingly.
4.5 KiB
4.5 KiB
| language | extensions | ||||
|---|---|---|---|---|---|
| ruby |
|
Ruby — Language-Specific Review Notes
Load this file alongside rules/universal.md. Universal rules are not repeated here — only Ruby-specific rules and idioms.
PR Analyzer — Ruby Risk Signals
puts/p/ppdebug statements left in production code# rubocop:disablecomments — verify they are justifiedeval/instance_eval/class_evalwith user-controlled input- Hardcoded credentials, tokens, or
SECRET_KEY_BASEin source binding.pry/byebug/debuggerleft in code
Code Quality — Ruby Checks
- Methods longer than 15 lines — Ruby idioms favor very small methods
- Classes with more than 10 public methods — possible god object
rescue Exception— catchesSignalExceptionandSystemExit; userescue StandardErroror more specific typesmethod_missingimplemented withoutrespond_to_missing?- Deeply nested blocks (>3 levels) — extract to methods
- String interpolation used where a symbol would suffice (hash keys, etc.)
Security
- Flag
eval/instance_evalwith user-controlled strings — remote code execution - Flag
system()/exec()/ backtick calls with user-controlled input — shell injection - Flag
YAML.loadon untrusted data — useYAML.safe_load - Flag
Marshal.loadon untrusted data — arbitrary code execution - Flag raw SQL string interpolation in ActiveRecord — use parameterized queries (
where("name = ?", name)) - Flag
paramspassed directly toredirect_towithout validation — open redirect - Flag
render inline:with user data — XSS via ERB - Flag missing
strong_parametersin Rails controllers — mass assignment vulnerability
Async / Concurrency
- Flag shared mutable state accessed from multiple threads without a
Mutex - Flag
Thread.newwithout storing the thread reference — exceptions are silently swallowed - Flag
sleepused as a synchronization mechanism in threaded code - Flag
@@class_variablesmutated in multi-threaded contexts — not thread-safe - Flag Sidekiq / ActiveJob workers that are not idempotent — jobs can be retried
Resource Management
- Flag
File.openwithout a block form — the block form guaranteesclose - Flag database connections or HTTP clients not released in
ensureblocks - Flag
ActiveRecordqueries inside loops — N+1 pattern; useincludes/preload/eager_load - Flag
ObjectSpaceusage in production — memory and performance impact
Exception Handling
- Flag
rescue Exception— userescue StandardErroror a specific exception class - Flag empty
rescueblocks — swallowed errors - Flag
rescueused for control flow (e.g. rescuingActiveRecord::RecordNotFoundinstead of usingfind_by) - Flag re-raising with
raise einstead of bareraise— loses the original backtrace - Flag
ensureblocks that can raise — masks the original exception
Performance
- Flag N+1 ActiveRecord queries — use
includes,preload, oreager_load - Flag
Array#eachwith string concatenation — usemap+join - Flag
select+mapthat could be a singlefilter_map - Flag
.counton an ActiveRecord relation inside a view or loop — triggers a query each time - Flag
requireinside a method body — constant overhead on every call - Flag
Hash#mergein a loop — usemerge!oreach_with_object
Idioms and Best Practices
Ruby Style
- Prefer
map/select/reject/reduceover manualeach+ accumulator - Prefer
&method(:name)over{ |x| some_method(x) }for method reference blocks - Prefer
freezeon string constants to avoid repeated object allocation - Use
attr_reader/attr_writer/attr_accessorinstead of manual getter/setter methods - Prefer
Symbol#to_proc(&:method_name) for simple single-method blocks
Rails-Specific
- Keep controllers thin — logic belongs in service objects, models, or concerns
- Use
before_actionfor authentication/authorization checks — never inline - Prefer
find_byoverwhere(...).first— more intent-revealing - Flag
after_commitcallbacks with side effects that should be in a service object - Prefer
respond_toblocks over separate controller actions for format variants
Modern Ruby (3.x)
- Prefer pattern matching (
case/in) for complex data destructuring - Use numbered block parameters (
_1,_2) only for very short, obvious blocks - Prefer
Data.definefor simple immutable value objects (Ruby 3.2+)