Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add ThibautBaissac/rails_ai_agents --skill multi-tenant-setupgit clone --depth 1 https://github.com/ThibautBaissac/rails_ai_agentsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/thibautbaissac/rails_ai_agents/multi-tenant-setup)<a href="https://agentmods.dev/skills/thibautbaissac/rails_ai_agents/multi-tenant-setup"><img src="https://agentmods.dev/badge/skills/thibautbaissac/rails_ai_agents/multi-tenant-setup/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/thibautbaissac/rails_ai_agents/multi-tenant-setup"><img src="https://agentmods.dev/badge/skills/thibautbaissac/rails_ai_agents/multi-tenant-setup.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00084 | $0.02559 |
| Opus 5 | $0.00042 | $0.01280 |
| Sonnet 5 | $0.00017 | $0.00512 |
| Haiku 4.5 | $0.00008 | $0.00256 |
Grade A, and why
multi-tenant-setup scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
1 near-identical copy found in the catalogue:
- multi-tenant-setup — 100% identical, 0 lines differ
How it starts
The opening of the file, as written. The whole thing — 430 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Multi-Tenant Setup
Philosophy: URL-Based Multi-Tenancy, Not Subdomain or Schema
- URL-based:
app.myapp.com/123/boards/456(account_id in path) account_idon every table (no foreign key constraints)Current.accountset from URL params for all requests- All queries scoped through
Current.account - UUIDs everywhere (prevents enumeration attacks)
- No default scopes (explicit scoping preferred)
- No Apartment gem, no subdomain routing, no schema separation
Project Knowledge
Stack: URL-based multi-tenancy (/accounts/:account_id/...), Current
attributes for account/user context, UUIDs for all primary keys, single
database with single schema.
Auth: Custom passwordless with Current.user, users can belong to multiple
accounts, account membership controls access.
Commands:
rails generate model Account name:string
rails generate model Membership user:references account:references role:integer
rails generate migration AddAccountToCards account:references
Pattern 1: Account Model and Memberships
See @references/membership-patterns.md for full details.
# app/models/account.rb
class Account < ApplicationRecord
has_many :memberships, dependent: :destroy
has_many :users, through: :memberships
has_many :boards, dependent: :destroy
has_many :cards, dependent: :destroy
validates :name, presence: true, length: { maximum: 100 }
def member?(user)
users.exists?(user.id)
end
def add_member(user, role: :member)
memberships.find_or_create_by!(user: user) do |membership|
membership.role = role
end
end
def owner
memberships.owner.first&.user
end
end
# app/models/membership.rb
class Membership < ApplicationRecord
belongs_to :user
belongs_to :account
enum :role, { member: 0, admin: 1, owner: 2 }
validates :user_id, uniqueness: { scope: :account_id }
validates :role, presence: true
scope :active, -> { where(active: true) }
end
# app/models/user.rb
class User < ApplicationRecord
has_many :memberships, dependent: :destroy
has_many :accounts, through: :memberships
def member_of?(account)
accounts.exists?(account.id)
end
def role_in(account)
memberships.find_by(account: account)&.role
end
def admin_of?(account)
memberships.find_by(account: account)&.admin? ||
memberships.find_by(account: account)&.owner?
end
end
What ships with it
2 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 430 lines · 84 tokens per session scan A ec6a146a2f1c
multi-tenant-setup is a skill published in the GitHub repository ThibautBaissac/rails_ai_agents (661 stars, last pushed 3mo ago), licensed MIT. It adds 84 tokens to every session and 2,559 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
event-store-design
Design and implement event stores for event-sourced systems. Use when building event sourcing infrastructure, choosing event store technologies, or implementing event persistence patterns.
convex-explain-app
Explain an existing Convex app — data model + relationships, public vs internal functions, auth/ownership model, components, a request→data flow — read from the schema and function surface. Read-only.
platform-custom-field-generate
Use this skill when users need to create, generate, or validate Salesforce Custom Field metadata. Trigger when users mention custom fields, field types, Roll-up Summary fields, Master-Detail relationships, Lookup relationships, formula fields, picklists, dependent (controlling) picklists, referencing a value set from…
field-service-sobject-create-configure
Headless 360 REST API deployment step for creating sObject records. Handles describe-based field discovery, required-field derivation, entity-relationship ordering, and composite graph transactions. Use this skill when a designer skill (or a user directly) needs to create sObject records after design confirmation…
durable-objects
Build, debug, or review Cloudflare Durable Objects code for persistent state and coordination.
nornicdb-grpc
Drive NornicDB over gRPC — the Qdrant-compatible surface (Collections, Points, Snapshots) plus the additive NornicSearch service. Use when ingesting via Qdrant SDKs, migrating from Qdrant, or running hybrid text+vector search from a non-Bolt client. Covers connection, RPC catalog, collection→database mapping…