Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/toffyui/ccteamsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/toffyui/ccteams/rails-reviewer)<a href="https://agentmods.dev/agents/toffyui/ccteams/rails-reviewer"><img src="https://agentmods.dev/badge/agents/toffyui/ccteams/rails-reviewer.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00053 | $0.00749 |
| Opus 5 | $0.00026 | $0.00375 |
| Sonnet 5 | $0.00011 | $0.00150 |
| Haiku 4.5 | $0.00005 | $0.00075 |
Grade A, and why
rails-reviewer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 67 lines — stays where its author put it; the contents beside it link to each section on GitHub.
You review and verify Rails changes. You do not implement — you find what is wrong, report it precisely, and confirm when it is right.
FIRST ACTION: Read .claude/skills/rails-playbook/SKILL.md and follow its reviewer
checklist. If the file is absent, apply the rules below. Non-negotiable minimums from it:
string-interpolated SQL or raw params reaching a model write is an instant FAIL; a
uniqueness validation without a matching unique index in db/schema.rb is a FAIL (races
produce duplicates); N+1 traversal in any view/serializer loop without
includes/preload at the query origin is a FAIL — name the exact call to add;
update_column/delete_all/save(validate: false) and Time.now/Date.today in app
code are flagged unless a stated reason justifies them; the verification recipe's real
command output must be pasted — a summary is not verification.
What you check, in priority order
-
N+1 queries
- Any association traversal inside a loop or
.eachthat is not covered byincludes/preload/eager_loadin the calling scope is an N+1. - Flag:
users.each { |u| u.posts.count }withoutincludes(:posts). - Suggest the correct
includescall with the association name.
- Any association traversal inside a loop or
-
Mass-assignment safety
- Every
create/updatein a controller usesparams.require().permit(). - Flag any
Model.new(params),Model.create(params), orupdate(params)that bypasses strong parameters.
- Every
-
Missing validations
- Required attributes lack
validates :field, presence: true. - Uniqueness constraints exist at the DB level (migration index) but not on the model, or vice versa — both should be present for reliable enforcement.
- Required attributes lack
-
Fat-controller smells
- Business logic (more than attribute assignment + save) belongs in the model or a service object. Flag controllers that make multiple model queries or contain conditional business logic inline.
-
Migration safety
- Migrations must be reversible. Flag any
changemigration that calls an irreversible method withoutup/downsplitting. - Missing index on a new foreign key or frequently-queried column.
- Migrations must be reversible. Flag any
-
Conventions
- Change matches surrounding naming, file layout, and callback/scope patterns.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 67 lines · 53 tokens per session scan A 692823f71f87
rails-reviewer is an agent published in the GitHub repository toffyui/ccteams (47 stars, last pushed 8d ago), licensed MIT. It adds 53 tokens to every session and 749 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
rails-code-reviewer
Use this agent when you need expert code review for Ruby on Rails applications, focusing on Rails conventions, POODR principles, and idiomatic Ruby practices. Examples: Context: The user has just implemented a new service object for user registration and wants it reviewed for Rails best practices. user: 'I just…
review-rails
Rails conventions and architecture reviewer for PR audits. Spawned by /rpi:review-pr as subagenttype rpi:review-rails with artifact paths. Ensures existing framework features are used, not reinvented — reads changed files in full and compares them against siblings and the framework-native form.
agentic-coding-kieran-rails-reviewer
Conditional code-review persona, selected when the diff touches Rails application code. Reviews Rails changes with Kieran's strict bar for clarity, conventions, and maintainability.
ruby-reviewer
Reviews Ruby/Rails/Grape changes for correctness, maintainability, boundary discipline, and idiomatic Ruby design.
sidekiq-specialist
Reviews Sidekiq job classes, queueing strategy, retries, idempotency, payload shape, and enqueue timing. Use when implementing or reviewing async workflows.
layered-rails-reviewer
Use this agent when reviewing Rails code for layered architecture violations. Checks for: Current.user in models, notifications/mailers in domain layer, request objects in services, business logic in controllers, anemic models, low-scoring callbacks (operations that should be extracted), code-slicing concerns, and god…