Django Access Review
getsentry/skills
Django access control and IDOR security review. An agent skill from getsentry/skills.
Guidance for building and debugging Phoenix web interfaces: where LiveView loads data, scopes, PubSub topics, external polling and component state.
$ npx skills add georgeguimaraes/elixir-agent-tools --skill phoenix -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install georgeguimaraes/elixir-agent-tools phoenix --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/georgeguimaraes/elixir-agent-tools.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/elixir-dev/skills/phoenix .claude/skills/phoenix && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "phoenix" agent skill from https://github.com/georgeguimaraes/elixir-agent-tools/tree/main/plugins/elixir-dev/skills/phoenix into .claude/skills/phoenix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phoenix", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/georgeguimaraes/elixir-agent-tools/tree/main/plugins/elixir-dev/skills/phoenixType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add georgeguimaraes/elixir-agent-tools --skill phoenix -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install georgeguimaraes/elixir-agent-tools phoenix --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/georgeguimaraes/elixir-agent-tools.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/elixir-dev/skills/phoenix .agents/skills/phoenix && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "phoenix" agent skill from https://github.com/georgeguimaraes/elixir-agent-tools/tree/main/plugins/elixir-dev/skills/phoenix into .agents/skills/phoenix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phoenix", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add georgeguimaraes/elixir-agent-tools --skill phoenix -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install georgeguimaraes/elixir-agent-tools phoenix --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/georgeguimaraes/elixir-agent-tools.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/elixir-dev/skills/phoenix .cursor/skills/phoenix && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "phoenix" agent skill from https://github.com/georgeguimaraes/elixir-agent-tools/tree/main/plugins/elixir-dev/skills/phoenix into .cursor/skills/phoenix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phoenix", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/georgeguimaraes/elixir-agent-tools.git --path plugins/elixir-dev/skills/phoenix--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add georgeguimaraes/elixir-agent-tools --skill phoenix -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install georgeguimaraes/elixir-agent-tools phoenix --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/georgeguimaraes/elixir-agent-tools.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/elixir-dev/skills/phoenix .gemini/skills/phoenix && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "phoenix" agent skill from https://github.com/georgeguimaraes/elixir-agent-tools/tree/main/plugins/elixir-dev/skills/phoenix into .gemini/skills/phoenix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phoenix", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install georgeguimaraes/elixir-agent-tools phoenixInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add georgeguimaraes/elixir-agent-tools --skill phoenix -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/georgeguimaraes/elixir-agent-tools.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/elixir-dev/skills/phoenix .github/skills/phoenix && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "phoenix" agent skill from https://github.com/georgeguimaraes/elixir-agent-tools/tree/main/plugins/elixir-dev/skills/phoenix into .github/skills/phoenix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phoenix", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add georgeguimaraes/elixir-agent-tools --skill phoenix -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install georgeguimaraes/elixir-agent-tools phoenix --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/georgeguimaraes/elixir-agent-tools.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/elixir-dev/skills/phoenix .opencode/skills/phoenix && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "phoenix" agent skill from https://github.com/georgeguimaraes/elixir-agent-tools/tree/main/plugins/elixir-dev/skills/phoenix into .opencode/skills/phoenix/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "phoenix", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
phoenixGuidance for building and debugging Phoenix web interfaces: where LiveView loads data, scopes, PubSub topics, external polling and component state.
The default is to load data in mount/3. The skill explains that mount and handle_params both run twice on first load, once as an HTTP dead render and once on the WebSocket connect, which is the LiveView lifecycle rather than a bug. handle_params/3 is for data that changes on live navigation through push_patch or patch links. When the double load really matters, it points to connected?(socket), assign_async/3 and assign_new/3 and notes what each one does not deduplicate.
Other patterns cover scopes, the Phoenix 1.8+ approach that threads authorization context through queries to prevent broken access control, PubSub topics that must be scoped by something like the organization or tenants see each other's data, external polling done by a single GenServer that broadcasts instead of every connected user calling the API, and the split between display-only functional components and LiveComponents that own state. The description also lists forms, routes, controllers, Plug and channels, and sends changesets and queries to the ecto skill.
Read from SKILL.md and the folder at commit ac3a5a1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are elixir).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Phoenix LiveView Patterns loads about 1.3k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 524 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from georgeguimaraes/elixir-agent-tools at commit ac3a5a1, republished under its Apache-2.0 licence (© georgeguimaraes). 524 words, ~1,307 tokens.
.claude/skills/phoenix/SKILL.md (or your agent's skills folder).Structure Phoenix interfaces, load LiveView data, and scope real-time updates.
Default: load data in mount/3.
def mount(_params, _session, socket) do
posts = Blog.list_posts(socket.assigns.current_scope)
{:ok, assign(socket, posts: posts)}
endYes, mount runs twice on initial load (HTTP dead render + WebSocket connect). So does handle_params/3. That's the LiveView lifecycle, not a bug to route around. Moving queries from mount to handle_params does not dedupe them.
Use handle_params/3 for data that changes on live navigation (push_patch / <.link patch={...}>). mount does not re-run on patches, handle_params does.
def handle_params(%{"filter" => filter}, _uri, socket) do
posts = Blog.list_posts(socket.assigns.current_scope, filter)
{:noreply, assign(socket, posts: posts, filter: filter)}
endWhen the initial double-load actually matters, the real tools are:
connected?(socket) to gate work to the connected render (loses SEO / no-JS rendering)assign_async/3 to load after mount returns, in a separate processassign_new/3 to reuse values already set on conn.assigns by upstream Plugs (e.g. :current_user), or shared from a parent LiveView. It does not dedupe arbitrary work across the dead/connected boundary: the function still runs on connected mount.def mount(_params, _session, socket) do
posts = if connected?(socket), do: Blog.list_posts(socket.assigns.current_scope), else: []
{:ok, assign(socket, posts: posts)}
endScopes address OWASP #1 vulnerability: Broken Access Control. Authorization context is threaded automatically—no more forgetting to scope queries.
def list_posts(%Scope{user: user}) do
Post |> where(user_id: ^user.id) |> Repo.all()
enddef subscribe(%Scope{organization: org}) do
Phoenix.PubSub.subscribe(@pubsub, "posts:org:#{org.id}")
endUnscoped topics = data leaks between tenants.
Bad: Every connected user makes API calls (multiplied by users). Good: Single GenServer polls, broadcasts to all via PubSub.
Use assign_async/3 for data that can load after mount:
def mount(_params, _session, socket) do
{:ok, assign_async(socket, :user, fn -> {:ok, %{user: fetch_user()}} end)}
endterminate/2 only fires if you're trapping exits—which you shouldn't do in LiveView.
Fix: Use a separate GenServer that monitors the LiveView process via Process.monitor/1, then handle :DOWN messages to run cleanup.
Calling start_async with the same name while a task is in-flight: the later one wins, the previous task's result is ignored.
Fix: Call cancel_async/3 first if you want to abort the previous task.
The socket in handle_out intercept is a snapshot from subscription time, not current state.
Why: Socket is copied into fastlane lookup at subscription time for performance.
Fix: Use separate topics per role, or fetch current state explicitly.
When merging classes on components, precedence is determined by stylesheet order, not HTML order. If btn-primary appears later in the compiled CSS than bg-red-500, it wins regardless of HTML order.
Fix: Use variant props instead of class merging.
The :content_type in %Plug.Upload{} is user-provided. Always validate actual file contents (magic bytes) and rewrite filename/extension.
To verify webhook signatures, you need the raw body. But Plug.Parsers consumes it.
{:ok, body, conn} = Plug.Conn.read_body(conn)
verify_signature!(conn, body)
%{conn | body_params: JSON.decode!(body)}Don't use preserve_req_body: true—it keeps the entire body in memory for ALL requests.
%Plug.Upload{}.content_type for securityAny of these? Re-read the Gotchas section.
© georgeguimaraes, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in plugins/elixir-dev/skills/phoenix of georgeguimaraes/elixir-agent-tools.
Open the folder on GitHubat commit ac3a5a1
Phoenix LiveView Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Phoenix LiveView Patterns this skillgeorgeguimaraes/elixir-agent-tools | 184 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Django Access Reviewgetsentry/skills | 1k | 3 repos | ~2.6k | Automated safety check: Notes | Apache-2.0 | |
| Frontmcp Auth UIagentfront/frontmcp | 146 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | |
| Configuring Horizoncoollabsio/coolify | 63k | 4 repos | ~898 | Automated safety check: Pass | MIT | |
| Abp Authorizationabpframework/abp | 14k | — | ~1.3k | Automated safety check: Pass | LGPL-3.0 | |
| Tyrohasinhayder/tyro | 685 | — | ~1.4k | Automated safety check: Pass | MIT |
getsentry/skills
Django access control and IDOR security review. An agent skill from getsentry/skills.
agentfront/frontmcp
A skill your agent uses when customizing, branding, or replacing the built-in FrontMCP OAuth pages (the login, consent, federated-select, incremental-authorization, and error pages) with your own…
coollabsio/coolify
A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.
abpframework/abp
ABP permission system - PermissionDefinitionProvider, [Authorize] attribute, CheckPolicyAsync, IsGrantedAsync, ICurrentUser, IPermissionManager, multi-tenancy side.
hasinhayder/tyro
Framework-maintainer skill for the Tyro Laravel authorization package
MineTrax/minetrax
Handles Laravel Pulse setup, configuration, and custom card development.
georgeguimaraes/elixir-agent-tools
Designs and debugs Elixir persistence with Ecto: schemas, changesets, queries, preloads, migrations and multi-tenancy, kept within application contexts.
georgeguimaraes/elixir-agent-tools
Writes and refactors idiomatic Elixir modules and functions, with rules for pattern matching, error handling, protocols and when a process is really needed.
georgeguimaraes/elixir-agent-tools
Guidance for building and debugging durable background jobs in Elixir with Oban and Oban Pro, covering serialization, retries, uniqueness, chaining, chunking and workflows.
georgeguimaraes/elixir-agent-tools
Guides choices among GenServer, Supervisor, Task, Registry, ETS and Broadway when designing or debugging Elixir concurrency, state and fault recovery.
Works with
Categories
Guidance for building and debugging Phoenix web interfaces: where LiveView loads data, scopes, PubSub topics, external polling and component state. The default is to load data in mount/3. The skill explains that mount and handle_params both run twice on first load, once as an HTTP dead render and once on the WebSocket connect, which is the LiveView lifecycle rather than a bug.
Phoenix LiveView Patterns fits situations like: deciding whether LiveView data belongs in mount or handle_params; scoping PubSub topics and queries so tenants cannot see each other's data; debugging a LiveView that appears to load data twice; moving external API polling out of individual LiveViews.
Run `npx skills add georgeguimaraes/elixir-agent-tools --skill phoenix -a claude-code`. Or copy the skill folder (plugins/elixir-dev/skills/phoenix in georgeguimaraes/elixir-agent-tools) into .claude/skills/phoenix in your project. Claude Code loads it when a task matches its description.
Run `npx skills add georgeguimaraes/elixir-agent-tools --skill phoenix -a codex`. Or copy the skill folder (plugins/elixir-dev/skills/phoenix in georgeguimaraes/elixir-agent-tools) into .agents/skills/phoenix in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add georgeguimaraes/elixir-agent-tools --skill phoenix -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/phoenix, .gemini/skills/phoenix, .github/skills/phoenix and .opencode/skills/phoenix in your project.
SKILL.md names no scripts, command-line tools or credentials: Phoenix LiveView Patterns is instructions for the agent only. Our summary lists: An Elixir project that uses Phoenix.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Phoenix LiveView Patterns is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.3k tokens (SKILL.md is roughly 5.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Phoenix LiveView Patterns: Django Access Review (getsentry/skills, 1k stars), Frontmcp Auth UI (agentfront/frontmcp, 146 stars), Configuring Horizon (coollabsio/coolify, 63k stars) and Abp Authorization (abpframework/abp, 14k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
georgeguimaraes (a GitHub user) maintains it in georgeguimaraes/elixir-agent-tools, which has 184 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 20, 2026.
Source: georgeguimaraes/elixir-agent-tools on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.