Agent skill

Rails Security Multitenancy

by marckohlbrugge in marckohlbrugge/37signals-skills

Apply Rails security and multi-tenant safety practices including scoped queries, SSRF defenses, rate limiting, and tenant-scoped realtime updates.

No licenceAuto-check passedBackend & APIs

Install Rails Security Multitenancy

skills CLI
$ npx skills add marckohlbrugge/37signals-skills --skill rails-security-multitenancy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install marckohlbrugge/37signals-skills rails-security-multitenancy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/marckohlbrugge/37signals-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/rails-security-multitenancy .claude/skills/rails-security-multitenancy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
rails-security-multitenancy
GitHub stars
724
Token cost
~1.7k tokens
SKILL.md length
716 words
Files
1
Skills in repo
8
Repo updated
First seen
Licence
None found

At a glance

Apply Rails security and multi-tenant safety practices including scoped queries, SSRF defenses, rate limiting, and tenant-scoped realtime updates.

  • Implementing auth
  • SKILL.md covers Core Rules, Tenancy Architecture…, Scoped Lookups (defense in… and Authentication Hardening, plus 6 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tenant boundaries

What it does

Rails Security Multitenancy is an agent skill from marckohlbrugge/37signals-skills. Apply Rails security and multi-tenant safety practices including scoped queries, SSRF defenses, rate limiting, and tenant-scoped realtime updates. Use when implementing auth, webhooks, tenant boundaries, or security-sensitive endpoints.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Backend development, Web application vulnerabilities and Multi-tenancy. The repository describes itself as: Unofficial agent skills + reference guide that teach AI coding assistants to write Rails the 37signals way — extracted from Fizzy, Campfire, and DHH's code reviews.

When your agent uses it

  • Implementing auth
  • Tenant boundaries
  • Security-sensitive endpoints

Example prompts

  • “/rails-security-multitenancy”

What it can do on your machine

Read from SKILL.md and the folder at commit c58e7d5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are ruby).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Rails Security Multitenancy loads about 1.7k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 716 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 716 words (~1,715 tokens).

“Use for security-sensitive Rails work and tenant-boundary reviews. Patterns from Fizzy (path-based multi-tenant SaaS) and Campfire (single-tenant, bot APIs).”

— opening of SKILL.md by marckohlbrugge
name
rails-security-multitenancy
disable-model-invocation
true

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/rails-security-multitenancy of marckohlbrugge/37signals-skills.

Open the folder on GitHubat commit c58e7d5

Compare with similar skills

Rails Security Multitenancy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Rails Security Multitenancy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Rails Security Multitenancy this skillmarckohlbrugge/37signals-skills724—~1.7kAutomated safety check: PassNone
Cashier Stripe Developmentluadotsh/lua3431 repos~1.2kAutomated safety check: PassMIT
Django Access Reviewgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Springboot Securityaffaan-m/ECC277k5 repos~2kAutomated safety check: PassMIT
Laravel Securityaffaan-m/ECC277k3 repos~2kAutomated safety check: PassMIT
Web Ssrfs0ld13rr/pentestcode828—~660Automated safety check: WarnMIT

Similar skills

  • Handles Laravel Cashier Stripe integration including subscriptions, webhooks, Stripe Checkout, invoices, charges, refunds, trials, coupons, metered billing, and payment failure handling.

    343 GitHub starsUsed in 1 repo~1.2k tokens
    Backend & APIsAuto-check passed
  • Django Access Review

    getsentry/skills

    Official

    Django access control and IDOR security review. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 3 repos~2.6k tokens
    Backend & APIsAuto-check: notes
  • Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

    277k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check passed
  • Laravel Security

    affaan-m/ECC

    Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.

    277k GitHub starsUsed in 3 repos~2k tokens
    Backend & APIsAuto-check passed
  • Web Ssrf

    s0ld13rr/pentestcode

    Server-Side Request Forgery detection→internal-access→proof for web apps.

    828 GitHub stars~660 tokensUpdated 8 days ago
    Backend & APIsAuto-check: warnings
  • Frappe Errors API

    Impertio-Studio/Frappe_Claude_Skill_Package

    A skill your agent uses when debugging or handling API errors in Frappe/ERPNext v14/v15/v16.

    189 GitHub stars~4k tokensUpdated 24 days ago
    Backend & APIsAuto-check passed

More from marckohlbrugge/37signals-skills

All 8 skills in this repo
  • Rails Best Practices Core

    marckohlbrugge/37signals-skills

    Apply core Ruby on Rails best practices for architecture, naming, safety, and maintainability.

    724 GitHub stars~1.7k tokensUpdated 4 mo ago
    Auto-check passed
  • Rails Jobs

    marckohlbrugge/37signals-skills

    Apply best practices for Rails background jobs using simple orchestration, idempotency, and safe retries.

    724 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Dhh

    marckohlbrugge/37signals-skills

    Review Ruby/Rails code like DHH would - direct, opinionated, allergic to over-engineering.

    724 GitHub stars~2.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Rails Hotwire Realtime

    marckohlbrugge/37signals-skills

    Apply Hotwire, Turbo, Stimulus, and ActionCable best practices for real-time Rails interfaces.

    724 GitHub stars~1.9k tokensUpdated 4 mo ago
    Auto-check passed
  • Rails Migrations

    marckohlbrugge/37signals-skills

    Write and review Rails database migrations safely, including reversible changes, lock-aware operations, and rollout sequencing.

    724 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Rails Testing

    marckohlbrugge/37signals-skills

    Apply Rails testing standards with Minitest, fixtures, and pragmatic coverage boundaries.

    724 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Rails Security Multitenancy

What does Rails Security Multitenancy do?

Apply Rails security and multi-tenant safety practices including scoped queries, SSRF defenses, rate limiting, and tenant-scoped realtime updates. Rails Security Multitenancy is an agent skill from marckohlbrugge/37signals-skills. Apply Rails security and multi-tenant safety practices including scoped queries, SSRF defenses, rate limiting, and tenant-scoped realtime updates.

When should I use Rails Security Multitenancy?

Rails Security Multitenancy fits situations like: implementing auth; tenant boundaries; security-sensitive endpoints.

How do I install Rails Security Multitenancy in Claude Code?

Run `npx skills add marckohlbrugge/37signals-skills --skill rails-security-multitenancy -a claude-code`. Or copy the skill folder (skills/rails-security-multitenancy in marckohlbrugge/37signals-skills) into .claude/skills/rails-security-multitenancy in your project. Claude Code loads it when a task matches its description.

How do I install Rails Security Multitenancy in Codex?

Run `npx skills add marckohlbrugge/37signals-skills --skill rails-security-multitenancy -a codex`. Or copy the skill folder (skills/rails-security-multitenancy in marckohlbrugge/37signals-skills) into .agents/skills/rails-security-multitenancy in your project. Codex loads it when a task matches its description.

Can I use Rails Security Multitenancy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add marckohlbrugge/37signals-skills --skill rails-security-multitenancy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/rails-security-multitenancy, .gemini/skills/rails-security-multitenancy, .github/skills/rails-security-multitenancy and .opencode/skills/rails-security-multitenancy in your project.

What does Rails Security Multitenancy need to run?

SKILL.md names no scripts, command-line tools or credentials: Rails Security Multitenancy is instructions for the agent only.

Does Rails Security Multitenancy access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Rails Security Multitenancy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Rails Security Multitenancy use?

No licence was found for Rails Security Multitenancy or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Rails Security Multitenancy use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Rails Security Multitenancy?

Skills that share tags, products or a category with Rails Security Multitenancy: Cashier Stripe Development (luadotsh/lua, 343 stars), Django Access Review (getsentry/skills, 1k stars), Springboot Security (affaan-m/ECC, 277k stars) and Laravel Security (affaan-m/ECC, 277k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Rails Security Multitenancy?

marckohlbrugge (a GitHub user) maintains it in marckohlbrugge/37signals-skills, which has 724 GitHub stars. The repository holds 8 skills in this directory. The repository was last updated on June 9, 2026.

Source: marckohlbrugge/37signals-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.