Agent skill

Antipattern Prevention

by doorkeeper-gem in doorkeeper-gem/doorkeeper

Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

MITAuto-check passedBackend & APIs

Install Antipattern Prevention

skills CLI
$ npx skills add doorkeeper-gem/doorkeeper --skill antipattern-prevention -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install doorkeeper-gem/doorkeeper antipattern-prevention --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/doorkeeper-gem/doorkeeper.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/antipattern-prevention .claude/skills/antipattern-prevention && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
antipattern-prevention
GitHub stars
5.5k
Token cost
~1.1k tokens
SKILL.md length
173 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
MIT

At a glance

Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

  • Works in 10 steps: Ruby Iteration Instead of SQL → Fire and Forget (Missing Error Handling) → Inaudible Failures (Silent Save) → …
  • Writing new code
  • SKILL.md covers 1. Ruby Iteration Instead of SQL, 2. Fire and Forget (Missing…, 3. Inaudible Failures (Silent… and 4. Callback Complexity, plus 8 more sections
  • Calls bundle

What it does

Antipattern Prevention is an agent skill from doorkeeper-gem/doorkeeper. Avoid common Ruby and Rails antipatterns that degrade maintainability and performance. Use when writing new code, reviewing PRs, or refactoring existing code in Doorkeeper.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Backend development, Refactoring and OAuth and OpenID Connect. It works with Ruby and Ruby on Rails. The repository describes itself as: Doorkeeper is an OAuth 2 provider for Ruby on Rails / Grape. The licence is MIT.

When your agent uses it

  • Writing new code
  • Refactoring existing code in Doorkeeper

Example prompts

  • “/antipattern-prevention”

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Ruby Iteration Instead of SQL
  2. Fire and Forget (Missing Error Handling)
  3. Inaudible Failures (Silent Save)
  4. Callback Complexity
  5. Bare Rescue
  6. String Interpolation in SQL
  7. String Equality on Secrets
  8. Tight Coupling to ActiveRecord
  9. Shotgun Surgery
  10. Monolithic Methods

What it can do on your machine

Read from SKILL.md and the folder at commit 80f4eba. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bundle

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Antipattern Prevention loads about 1.1k tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 173 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from doorkeeper-gem/doorkeeper at commit 80f4eba, republished under its MIT licence (© doorkeeper-gem). 173 words, ~1,083 tokens.

Download SKILL.mdSave it as .claude/skills/antipattern-prevention/SKILL.md (or your agent's skills folder).
name
antipattern-prevention
description
Avoid common Ruby and Rails antipatterns that degrade maintainability and performance. Use when writing new code, reviewing PRs, or refactoring existing code in Doorkeeper.

Antipattern Prevention

When writing or reviewing code in Doorkeeper, use this skill to avoid common antipatterns that degrade maintainability and performance.

1. Ruby Iteration Instead of SQL

Severity: High

ruby
# BAD — loads all tokens into memory
AccessToken.all.select { |t| t.expired? }

# GOOD — push to database
# The codebase uses expiration_time_sql for this:
# lib/doorkeeper/models/concerns/expiration_time_sql_math.rb
ruby
# BAD
ids = AccessToken.pluck(:id).select { |id| id > 100 }

# GOOD
AccessToken.where("id > ?", 100).pluck(:id)

2. Fire and Forget (Missing Error Handling)

Severity: High

ruby
# BAD
def fetch_jwks(uri)
  response = Net::HTTP.get(URI(uri))
  JSON.parse(response)
rescue
  nil
end

# GOOD — use the existing HttpFetcher which handles timeouts and errors
# Reference: lib/doorkeeper/http_fetcher.rb
def fetch_jwks(uri)
  response = http_fetcher.fetch(uri)
  JSON.parse(response)
rescue HttpFetcher::FetchError => e
  Rails.logger.warn("JWKS fetch failed: #{e.message}")
  nil
end

3. Inaudible Failures (Silent Save)

Severity: Medium

ruby
# BAD — fails silently
token.save

# GOOD — raises on failure
token.save!

# ALSO GOOD — check return value
unless token.save
  handle_error(token.errors)
end

4. Callback Complexity

Severity: High

ruby
# BAD — hidden side effects
class AccessToken
  after_create :notify_admin, :update_metrics, :send_webhook
end

# GOOD — explicit orchestration in request objects
class AuthorizationCodeRequest
  def before_successful_response
    find_or_create_access_token(...)
    super
  end
end

Doorkeeper uses before_successful_response / after_successful_response hooks — this is the correct pattern.

5. Bare Rescue

Severity: High

ruby
# BAD — catches Exception, including SystemExit, Interrupt, NoMemoryError
rescue Exception => e
  nil
end

# BAD — swallows all StandardError subclasses indiscriminately
rescue
  nil
end

# GOOD — specific exception classes
rescue JWT::DecodeError, JWT::ExpiredSignature => e
  handle_jwt_error(e)
end

6. String Interpolation in SQL

Severity: Critical (security)

ruby
# BAD — SQL injection
where("token = '#{params[:token]}'")

# GOOD — parameterized
where(token: params[:token])
where("token = ?", params[:token])

7. String Equality on Secrets

Severity: Critical (security)

ruby
# BAD — timing attack
token == stored_token

# GOOD — constant-time
ActiveSupport::SecurityUtils.secure_compare(token, stored_token)

8. Tight Coupling to ActiveRecord

Severity: Medium

Doorkeeper supports multiple ORMs. Protocol logic in lib/doorkeeper/oauth/ should use the model mixin interface:

ruby
# BAD — AR-specific in protocol code
AccessToken.where(token: value).lock.first

# GOOD — use mixin method
AccessToken.by_token(value)

9. Shotgun Surgery

Severity: Medium

If adding a new token attribute requires editing 8+ files, consider whether the design is right. The custom_attributes pattern shows how to add token attributes generically without shotgun surgery.

10. Monolithic Methods

Severity: Medium

ruby
# BAD — one method doing too much
def authorize
  validate_client
  validate_scopes
  validate_redirect_uri
  create_grant
  generate_response
end

# GOOD — Doorkeeper's validation DSL
validate :client,        error: Errors::InvalidClient
validate :redirect_uri,  error: Errors::InvalidRedirectUri
validate :scopes,        error: Errors::InvalidScope

Quick Detection Patterns

bash
# Bare rescue
grep -rn "rescue$" lib/ app/

# Silent save
grep -rn "\.save$" lib/ app/

# SQL interpolation
grep -rn 'where(".*#\{' lib/ app/

# String equality on secrets
grep -rn '== .*token\|== .*secret\|token.* ==' lib/ app/

# Ruby filtering instead of SQL
grep -rn '\.all\.select\|\.all\.map\|\.all\.each' lib/ app/

Verification

After changes:

  1. bundle exec rubocop — catches many antipatterns automatically
  2. bundle exec rspec — ensures behavior hasn't regressed
  3. Manual review of the diff for the patterns above

© doorkeeper-gem, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/antipattern-prevention of doorkeeper-gem/doorkeeper.

Open the folder on GitHubat commit 80f4eba

Compare with similar skills

Antipattern Prevention next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Antipattern Prevention compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Antipattern Prevention this skilldoorkeeper-gem/doorkeeper5.5k—~1.1kAutomated safety check: PassMIT
Rubyericrisco/rsc-harness180—~3.2kAutomated safety check: PassMIT
Layered Railsevilmartians/redprints-cfp1081 repos~4.1kAutomated safety check: PassNone
Rails ArchitectureThibautBaissac/rails_ai_agents665—~1.5kAutomated safety check: PassMIT
Rails ExpertJeffallan/claude-skills12k—~1.4kAutomated safety check: PassMIT
Ruby Prodavila7/claude-code-templates33k8 repos~445Automated safety check: PassMIT

Similar skills

  • Ruby

    ericrisco/rsc-harness

    A skill your agent uses when writing or refactoring plain Ruby outside Rails — scripts, CLIs, gems, libraries: Enumerable chains and blocks, module mixins and value objects, Bundler/gemspec…

    180 GitHub stars~3.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Layered Rails

    evilmartians/redprints-cfp

    Write, refactor, and review Rails code using layered architecture principles from "Layered Design for Ruby on Rails Applications".

    108 GitHub starsUsed in 1 repo~4.1k tokens
    Backend & APIsAuto-check passed
  • Rails Architecture

    ThibautBaissac/rails_ai_agents

    Guides modern Rails 8 code architecture decisions and patterns.

    665 GitHub stars~1.5k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Rails Expert

    Jeffallan/claude-skills

    Builds Rails 7+ apps with Hotwire Turbo Frames and Streams, Active Record tuning, Action Cable, Sidekiq jobs and RSpec specs, with migration and N+1 checks.

    12k GitHub stars~1.4k tokensUpdated 7 days ago
    Backend & APIsAuto-check passed
  • Ruby Pro

    davila7/claude-code-templates

    Write idiomatic Ruby code with metaprogramming, Rails patterns, and performance optimization.

    33k GitHub starsUsed in 8 repos~445 tokens
    DevelopmentAuto-check passed
  • Rails Patterns

    affaan-m/ECC

    Ruby on Rails framework patterns for Rails 7.1+ and 8.x apps.

    276k GitHub stars~4.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from doorkeeper-gem/doorkeeper

  • Code Quality

    doorkeeper-gem/doorkeeper

    Maintain code health and architecture standards when implementing features or refactoring Doorkeeper.

    5.5k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Dependency Safety

    doorkeeper-gem/doorkeeper

    Ensure gems are safe, necessary, and properly constrained when adding, updating, or reviewing dependencies in Doorkeeper.

    5.5k GitHub stars~931 tokensUpdated yesterday
    Auto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Testing

    doorkeeper-gem/doorkeeper

    Write correct and complete RSpec tests for Doorkeeper. An agent skill from doorkeeper-gem/doorkeeper.

    5.5k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Rfc Compliance

    doorkeeper-gem/doorkeeper

    Verify OAuth protocol implementations stay aligned with relevant RFCs.

    5.5k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed

Questions about Antipattern Prevention

What does Antipattern Prevention do?

Avoid common Ruby and Rails antipatterns that degrade maintainability and performance. Antipattern Prevention is an agent skill from doorkeeper-gem/doorkeeper. Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

When should I use Antipattern Prevention?

Antipattern Prevention fits situations like: writing new code; refactoring existing code in Doorkeeper.

How do I install Antipattern Prevention in Claude Code?

Run `npx skills add doorkeeper-gem/doorkeeper --skill antipattern-prevention -a claude-code`. Or copy the skill folder (.agents/skills/antipattern-prevention in doorkeeper-gem/doorkeeper) into .claude/skills/antipattern-prevention in your project. Claude Code loads it when a task matches its description.

How do I install Antipattern Prevention in Codex?

Run `npx skills add doorkeeper-gem/doorkeeper --skill antipattern-prevention -a codex`. Or copy the skill folder (.agents/skills/antipattern-prevention in doorkeeper-gem/doorkeeper) into .agents/skills/antipattern-prevention in your project. Codex loads it when a task matches its description.

Can I use Antipattern Prevention in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add doorkeeper-gem/doorkeeper --skill antipattern-prevention -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/antipattern-prevention, .gemini/skills/antipattern-prevention, .github/skills/antipattern-prevention and .opencode/skills/antipattern-prevention in your project.

What does Antipattern Prevention need to run?

Going by SKILL.md and its folder, Antipattern Prevention needs the command-line tools its instructions call (bundle).

Does Antipattern Prevention access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Antipattern Prevention safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Antipattern Prevention use?

Antipattern Prevention is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Antipattern Prevention use?

About 1.1k tokens (SKILL.md is roughly 4.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Antipattern Prevention?

Skills that share tags, products or a category with Antipattern Prevention: Ruby (ericrisco/rsc-harness, 180 stars), Layered Rails (evilmartians/redprints-cfp, 108 stars), Rails Architecture (ThibautBaissac/rails_ai_agents, 665 stars) and Rails Expert (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Antipattern Prevention?

doorkeeper-gem (a GitHub organization) maintains it in doorkeeper-gem/doorkeeper, which has 5,523 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.

Source: doorkeeper-gem/doorkeeper on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.