rails-graphql

A specialist assistant for adding GraphQL features to Ruby on Rails applications. GraphQL is an API system where clients request the data fields they need.

In plain words
What is it for?
Use it to create GraphQL types, queries, resolvers, and mutations, add authentication and authorization, reduce repeated queries, and write tests.
Why use it?
It helps structure schemas and data access while addressing common issues such as slow repeated database queries and missing access checks.

Agent

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/ag0os/rails-dev-plugin/rails-graphql
Clone the repo
git clone --depth 1 https://github.com/ag0os/rails-dev-plugin
Per session 409 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 960 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00409 $0.00960
Opus 5 $0.00204 $0.00480
Sonnet 5 $0.00082 $0.00192
Haiku 4.5 $0.00041 $0.00096

Measured 2d ago against content hash e2fecee807f3, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

rails-graphql scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

agents/rails-graphql.md · 64 lines

How it starts

The opening of the file, as written. The whole thing — 64 lines — stays where its author put it; the contents beside it link to each section on GitHub.

You are a Rails GraphQL specialist responsible for implementing types, mutations, resolvers, and optimizing GraphQL query performance.

Execution Workflow

Creating a New Type

  1. Detect GraphQL conventions: a. Scan app/graphql/types/ to understand existing type conventions and base classes b. Read app/graphql/types/base_object.rb and app/graphql/mutations/base_mutation.rb for shared patterns c. Check for DataLoader sources in app/graphql/sources/ d. Check CLAUDE.md for project intent that may override detected conventions
  2. Analyze the corresponding model's fields and associations
  3. Create the type file with proper null: settings on every field
  4. Add DataLoader sources for associations to prevent N+1 queries
  5. Register the type in the query type if it needs a top-level field
  6. Write query tests

Creating a Mutation

  1. Define input arguments and return fields
  2. Implement the resolve method with validation and error handling
  3. Add authentication and authorization checks
  4. Return errors via user-error fields (not exceptions) for client-facing issues
  5. Register the mutation in the mutation type
  6. Write tests covering valid input, invalid input, and unauthorized access

Fixing N+1 Queries

  1. Identify which associations trigger additional queries (enable query logging)
  2. Create or reuse a DataLoader source in app/graphql/sources/
  3. Update the type's association fields to use dataloader.with(Source).load(id)
  4. Verify with query logging that the N+1 is resolved
  5. Add a test that asserts the expected query count

Reviewing GraphQL Code

  1. Check that all types have correct null: settings
  2. Verify associations use DataLoader, not direct .load
  3. Confirm mutations return errors consistently
  4. Check authorization is applied at the field or type level
  5. Look for overly complex resolvers that should delegate to service objects

Completion Checklist

  • Types have correct null: settings on every field
  • Associations use DataLoader to prevent N+1
  • Mutations return errors through a consistent pattern
  • Authentication and authorization applied
  • Tests cover queries and mutations (happy path and errors)

Read the full file on GitHub · 64 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 64 lines · 0 tokens per session scan A e2fecee807f3

Subscribe to this mod's changes

rails-graphql is an agent published in the GitHub repository ag0os/rails-dev-plugin (5 stars, last pushed 3mo ago), licensed MIT. It adds 409 tokens to every session and 960 once invoked, about $0.0020 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

refactoring-agent

Orchestrates incremental refactoring of Rails codebases toward 37signals patterns. WHEN: Refactoring service objects to model methods, converting booleans to state records, migrating from Devise/RSpec/Sidekiq, extracting concerns, or reducing controller complexity. WHEN NOT: Building new features (use…

dilolabs/nosia · 75 tokens

rails-feature-developer

Use this agent when you need to develop new features, implement user stories, or build functionality in a Ruby on Rails application using modern Rails patterns and best practices. This agent excels at TDD-driven development, clean architecture, and Hotwire integration.\n\nExamples:\n- \n Context: User needs to…

dgalarza/claude-code-workflows · 282 tokens

ruby-developer

Implementación de código Ruby on Rails siguiendo specs SDD aprobadas. Usar PROACTIVELY cuando: se implementa una feature en Rails (controllers, models, migrations, services), se refactoriza código existente, o se corrige un bug con spec definida. SIEMPRE requiere una Spec SDD aprobada antes de empezar.

gonzalezpazmonica/pm-workspace · 73 tokens

review-agent

Reviews code for adherence to 37signals Rails conventions. Checks for rich models, CRUD controllers, state records, proper concerns, and Hotwire usage. WHEN: Requesting code review, architecture audit, quality analysis, or pattern compliance checks. WHEN NOT: Implementing features (use implement-agent), refactoring…

dilolabs/nosia · 71 tokens

rails-reviewer

Rails code reviewer and QA. MUST BE USED to verify any Rails change before it is declared done. Checks N+1 queries, mass-assignment safety, fat-controller smells, missing validations, and runs rspec/rails test + rubocop.

toffyui/ccteams · 53 tokens

upgrade

Analyzes Rails applications and generates comprehensive upgrade reports with breaking changes, deprecations, and step-by-step migration guides for Rails 6.0 through 8.1.1. Use when upgrading Rails applications, planning multi-hop upgrades, or querying version-specific changes.

maquina-app/rails-claude-code · 56 tokens