Token导航 LogoToken导航TokenDH.com
待分类需要联网github未标认证来源可访问clear审计通过

ecto-patterns外型

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

3,609

周安装

146

GitHub Stars

39

下载量

1,133
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:ecto-patterns(外型)
来源仓库:https://github.com/bobmatnyc/claude-mpm-skills
仓库路径:skills/ecto-patterns
安装命令:
npx skills add https://github.com/bobmatnyc/claude-mpm-skills --skill ecto-patterns
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/bobmatnyc/claude-mpm-skills --skill ecto-patterns

简介

用于辅助安全审计、权限检查和认证流程分析,帮助识别凭据风险和常见漏洞。

  • 适合梳理敏感配置、检查依赖风险或生成安全复核清单。
  • 不能将工具输出直接作为最终结论,涉及密钥或生产系统时应先确认最小权限。
  • 安装方式:通过 npx skills add 命令从指定 GitHub 仓库安装。
  • 建议确认权限范围和维护状态,避免触发不必要的文件操作或网络请求。

SKILL.md

Ecto Patterns for Phoenix/Elixir

Ecto is the data layer for Phoenix applications: schemas, changesets, queries, migrations, and transactions. Good Ecto practice keeps domain logic in contexts, enforces constraints in the database, and uses transactions for multi-step workflows.

Schemas and Changesets

defmodule MyApp.Accounts.User do
  use Ecto.Schema
  import Ecto.Changeset

  schema "users" do
    field :email, :string
    field :hashed_password, :string
    field :confirmed_at, :naive_datetime
    has_many :memberships, MyApp.Orgs.Membership
    timestamps()
  end

  def registration_changeset(user, attrs) do
    user
    |> cast(attrs, [:email, :password])
    |> validate_required([:email, :password])
    |> validate_format(:email, ~r/@/)
    |> validate_length(:password, min: 12)
    |> unique_constraint(:email)
    |> hash_password()
  end

  defp hash_password(%{valid?: true} = cs),
    do: put_change(cs, :hashed_password, Argon2.hash_pwd_salt(get_change(cs, :password)))
  defp hash_password(cs), do: cs
end

Guidelines

  • Keep casting/validation in changesets; keep business logic in contexts.
  • Always pair validation with DB constraints (unique_constraint, foreign_key_constraint).
  • Use changeset/2 for updates; avoid mass assigning without casting.

Migrations

def change do
  create table(:users) do
    add :email, :citext, null: false
    add :hashed_password, :string, null: false
    add :confirmed_at, :naive_datetime
    timestamps()
  end

  create unique_index(:users, [:email])
end

Safe migration tips

  • Prefer additive changes: add columns nullable, backfill, then enforce null: false.
  • For large tables: use concurrently: true for indexes; disable in change and wrap in up/down for Postgres.
  • Data migrations belong in separate modules called from mix ecto.migrate via execute/1 or in distinct scripts; ensure idempotence.
  • Coordinate locks: avoid long transactions; break migrations into small steps.

Queries and Preloads

import Ecto.Query

def list_users(opts \\ %{}) do
  base =
    from u in MyApp.Accounts.User,
      preload: [:memberships],
      order_by: [desc: u.inserted_at]

  Repo.all(apply_pagination(base, opts))
end

defp apply_pagination(query, %{limit: limit, offset: offset}),
  do: query |> limit(^limit) |> offset(^offset)
defp apply_pagination(query, _), do: query

Patterns

  • Use preload rather than calling Repo in loops; prefer Repo.preload/2 after fetching.
  • Use select to avoid loading large blobs.
  • For concurrency, use Repo.transaction with lock: "FOR UPDATE" in queries that need row-level locks.

Transactions and Ecto.Multi

alias Ecto.Multi

def onboard_user(attrs) do
  Multi.new()
  |> Multi.insert(:user, User.registration_changeset(%User{}, attrs))
  |> Multi.insert(:org, fn %{user: user} ->
    Org.changeset(%Org{}, %{owner_id: user.id, name: attrs["org_name"]})
  end)
  |> Multi.run(:welcome, fn _repo, %{user: user} ->
    MyApp.Mailer.deliver_welcome(user)
    {:ok, :sent}
  end)
  |> Repo.transaction()
end

Guidelines

  • Prefer Multi.run/3 for side effects that can fail; return {:ok, value} or {:error, reason}.
  • Use Multi.update_all for batch updates; include where guards to prevent unbounded writes.
  • Propagate errors upward; translate them in controllers/LiveViews.

Associations and Constraints

  • Use on_replace::delete/:nilify to control nested changes.
  • Define foreign_key_constraint/3 and unique_constraint/3 in changesets to surface DB errors cleanly.
  • For many-to-many, prefer join schema (has_many:memberships) instead of automatic many_to_many when you need metadata.

Pagination and Filtering

  • Offset/limit for small datasets; cursor-based for large lists (Scrivener, Flop, Paginator).
  • Normalize filters in contexts; avoid letting controllers build queries directly.
  • Add composite indexes to match filter columns; verify with EXPLAIN ANALYZE.

Multi-Tenancy Patterns

  • Prefix-based: Postgres schemas per tenant (put_source/2 with prefix:) — good isolation, needs per-tenant migrations.
  • Row-based: tenant_id column + row filters — simpler migrations; add partial indexes per tenant when large.
  • Always scope queries by tenant in contexts; consider using policies/guards to enforce.

Performance and Ops

  • Use Repo.stream for large exports; wrap in Repo.transaction.
  • Cache hot reads with ETS/Cachex; invalidate on writes.
  • Watch query counts in LiveView/Channels; preload before rendering to avoid N+1.
  • Telemetry: OpentelemetryEcto exports query timings; add DB connection pool metrics.

Testing

use MyApp.DataCase, async: true

test "registration changeset validates email" do
  changeset = User.registration_changeset(%User{}, %{email: "bad", password: "secretsecret"})
  refute changeset.valid?
  assert %{email: ["has invalid format"]} = errors_on(changeset)
end
  • DataCase sets up sandboxed DB; keep tests async unless transactions conflict.
  • Use factories/fixtures in test/support to build valid structs quickly.
  • For migrations, add regression tests for constraints (unique/index-backed constraints).

Common Pitfalls

  • Running risky DDL in a single migration step (avoid locks; break apart).
  • Skipping DB constraints and relying only on changesets.
  • Querying associations in loops instead of preloading.
  • Missing transactions for multi-step writes (partial state on failure).
  • Forgetting tenant scoping on read/write in multi-tenant setups.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Claude Code

27.26%
按下载量换算309

Gemini CLI

25.04%
按下载量换算284

OpenCode

18.07%
按下载量换算205

Antigravity

11.57%
按下载量换算131

github-copilot

8.42%
按下载量换算95

Codex

3.66%
按下载量换算41

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。

来源信息

继续浏览同类 Skills