bundled-skills/super-code/ruby/SKILL.md
Language-specific super-code guidelines for ruby.
npx skillsauth add FrancoStino/opencode-skills-antigravity rubyInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
# ❌ Manual accumulation
result = []
items.each do |item|
result << item.name.upcase if item.active?
end
# ✅
result = items.select(&:active?).map { |i| i.name.upcase }
# ❌ Manual grouping
grouped = {}
items.each do |item|
grouped[item.category] ||= []
grouped[item.category] << item
end
# ✅
grouped = items.group_by(&:category)
# ❌ Manual sum
total = 0
orders.each { |o| total += o.amount }
# ✅
total = orders.sum(&:amount)
# ❌ Checking existence then accessing
if hash.key?(key)
value = hash[key]
end
# ✅
value = hash[key] # returns nil if missing
# or with default:
value = hash.fetch(key, default_value)
# or raising on missing:
value = hash.fetch(key) # raises KeyError
Prefer map/select/reject/sum over manual loops. Use &:method for single-method blocks.
# ❌ Explicit block-to-proc conversion when unnecessary
items.map { |item| item.to_s }
# ✅
items.map(&:to_s)
# ❌ Proc.new when lambda is safer (arity check + return behavior)
handler = Proc.new { |x| x * 2 }
# ✅
handler = ->(x) { x * 2 }
# ❌ Multi-line block with { }
items.map { |item|
result = transform(item)
validate(result)
result
}
# ✅ — do/end for multi-line, { } for single-line
items.map do |item|
result = transform(item)
validate(result)
result
end
# ❌ String concatenation in loop
result = ""
items.each { |i| result += i.name + ", " }
# ✅
result = items.map(&:name).join(", ")
# ❌ String concatenation for assembly
greeting = "Hello, " + name + "! You have " + count.to_s + " messages."
# ✅
greeting = "Hello, #{name}! You have #{count} messages."
# ❌ Mutable string where frozen is fine (Ruby 3+ encourages frozen)
SEPARATOR = ", "
# ✅
SEPARATOR = ", ".freeze
# or add `# frozen_string_literal: true` at file top
Use heredocs (<<~HEREDOC) for multi-line strings. <<~ strips indentation.
# ❌ Rescuing Exception (catches EVERYTHING including SignalException, SystemExit)
begin
risky
rescue Exception => e
log(e)
end
# ✅ — rescue StandardError (the default)
begin
risky
rescue StandardError => e
log(e)
raise
end
# or just: rescue => e (same as StandardError)
# ❌ Using rescue as flow control
begin
value = hash.fetch(key)
rescue KeyError
value = default
end
# ✅
value = hash.fetch(key, default)
# ❌ Inline rescue hiding errors
result = dangerous_operation rescue nil
# ✅ — inline rescue only for truly trivial fallbacks
result = Integer(input) rescue nil # acceptable for parsing
# ❌ Manual accessors
class User
def name
@name
end
def name=(value)
@name = value
end
end
# ✅
class User
attr_accessor :name
end
# ❌ Deep inheritance for shared behavior
class Animal; end
class Pet < Animal; end
class Dog < Pet; end
# ✅ — mixins for shared behavior, inheritance for "is-a"
module Trainable
def train = puts("Training #{name}")
end
class Dog
include Trainable
attr_reader :name
def initialize(name) = @name = name
end
# ❌ Class with only class methods (namespace via class)
class MathUtils
def self.square(x) = x * x
def self.cube(x) = x ** 3
end
# ✅
module MathUtils
module_function
def square(x) = x * x
def cube(x) = x ** 3
end
# ❌ Explicit boolean return
def active?
if status == :active
true
else
false
end
end
# ✅
def active? = status == :active
# ❌ nil check before method call
if user && user.name
puts user.name
end
# ✅ (Ruby 2.3+)
puts user&.name if user&.name
# or with safe navigation:
user&.name&.then { |n| puts n }
# ❌ Conditional assignment verbosely
if @cache.nil?
@cache = expensive_compute
end
# ✅
@cache ||= expensive_compute
# ❌ Multiple assignment from array manually
first = arr[0]
second = arr[1]
# ✅
first, second = arr
| Anti-pattern | Preferred |
|---|---|
| rescue Exception | rescue StandardError |
| for x in collection | collection.each |
| Manual attr_reader/writer | attr_accessor / attr_reader |
| class for pure namespace | module |
| String concatenation with + | string interpolation #{} |
| if !condition | unless condition |
| == true / == false | truthy/falsy check directly |
| and/or for control flow | &&/|| (different precedence) |
| return at end of method | implicit return (last expression) |
| Monkey-patching core classes in production | refinements or wrapper |
| eval / send for known methods | direct method call |
tools
Authorized security assessment of LLM applications and AI agents: prompt injection, tool abuse, RAG exposure, memory poisoning, system-prompt extraction, and agent-compliance engineering per OWASP LLM/ASI Top 10.
development
Builds two parameterized UI modes—流光溢彩白 (iridescent white) and 五彩斑斓黑 (colorful black)—with OKLCH, WebGL/CSS fallback, vision gating, screenshot QA, and total/per-color intensity reports. Use when a UI request names either mode or needs measured color parameters.
tools
Delegate coding tasks to the Kimi Code CLI (`kimi`) only when the user explicitly requests it, while the orchestrator retains review and landing responsibility.
development
Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.