Claude Code skills · updated 2026-10-03

Rails ERB XSS audit skill for Claude Code — raw/html_safe, script-tag escaping

Finds each raw, html_safe, <%== and <script> value that skips Rails escaping

rails-erb-xss-audit - findings on the bundled example

On one 32-line Rails product page it printed 15 findings (11 errors, 4 warnings) from 15 rules, each with file:line, what breaks and the replacement line.

Get it on Whop - $12 onceGet it on Gumroad

What it printed on the bundled example

== ERB Escape Audit — 15 findings (11 errors, 4 warnings) in 1 file · 15 rules
  CRITICAL escape-sample.erb:6  [raw_helper]
        raw() turns the value into HTML and skips escaping - a stored '<script>' in that value runs in every visitor's browser. Drop raw() (<%= value %> escapes by default) or use sanitize(value, tags: %w[b i a]).
  CRITICAL escape-sample.erb:7  [html_safe_call]
        #html_safe marks the string as already-escaped, so ERB prints it verbatim. Remove .html_safe, or build the markup with tag helpers (content_tag/safe_join) so only the literal parts are trusted.
  CRITICAL escape-sample.erb:8  [double_equals_tag]
        <%== is the shorthand for <%= raw - identical unescaped output with no visible 'raw' to grep for. Change it to <%= and escape explicitly where you really need HTML.
  CRITICAL escape-sample.erb:10  [render_inline]
        render inline: compiles the string as an ERB template; user text reaching it is server-side template injection, not just XSS. Render a real template file and pass the value as a local.

What you get

Install

Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "Can you check our Rails views for XSS? Don't edit anything yet.". Needs Node 16+.

unzip rails-erb-xss-audit.zip -d ~/.claude/skills/

Ask Claude

“Can you check our Rails views for XSS? Don't edit anything yet.”

What it does not do

Reads .erb files only - no Ruby helpers, Haml or Slim; it does not boot Rails or trace data flow, and it is not a replacement for Brakeman.

FAQ

What is a Claude Code skill?

A folder with a SKILL.md and scripts that Claude Code loads when your request matches it. You ask in plain words and Claude runs the scanner the skill carries.

How is this different from asking Claude without the skill?

The skill carries a dated rule table and a scanner that reads every file, so Claude quotes the exact date and line instead of answering from memory.

Does it send my code anywhere?

Reads .erb files only - no Ruby helpers, Haml or Slim; it does not boot Rails or trace data flow, and it is not a replacement for Brakeman.

How do I install it?

Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "Can you check our Rails views for XSS? Don't edit anything yet.". Needs Node 16+.

What do I get when I buy?

The zip. On Whop it is in your library as a download lesson with the zip attached; on Gumroad it is the product file.