SkillAgentSearch skills...

ash-framework

Ash Framework — resources, actions, policies, aggregates, calculations, AshPhoenix.Form, LiveView, migrations

Install / Use

npx skills add oliver-kriska/claude-elixir-phoenix --skill ash-framework

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

84/100

Category

Security

Supported Platforms

Universal

Our assessment of ash-framework

ash-framework scores 84/100 on our quality scale, 819th of 1,120 Security skills we index.

Its SKILL.md is 5.3 KB long, well organised into 14 sections with 4 code examples: a solid amount of guidance for an agent.

It has 560 GitHub stars, a meaningful sign that others use it.

Substance
26/30
Structure
20/20
Description
12/15
Adoption
12/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 3 days ago, so ash-framework is actively maintained.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

ash-framework compared with similar skills

All 4 of these similar skills score higher than ash-framework; compare them before choosing.

SkillScoreStarsUpdatedFormat
ash-framework (this skill)by oliver-kriska845603d agoSKILL.md
algorithmic-artby anthropics100177.9k13d agoSKILL.md
pptxby anthropics100177.9k13d agoSKILL.md
designby nextlevelbuilder100130.2k14d agoSKILL.md
ui-ux-pro-maxby nextlevelbuilder100130.2k14d agoSKILL.md

Frequently asked questions

How do I install ash-framework?
Run npx skills add oliver-kriska/claude-elixir-phoenix --skill ash-framework. The install tabs above show the steps for each supported agent.
Which AI agents does ash-framework work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is ash-framework safe to use?
It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is ash-framework still maintained?
The repository was last updated 3 days ago, so ash-framework is actively maintained.

name: ash-framework description: "Ash Framework — resources, actions, policies, aggregates, calculations, AshPhoenix.Form, LiveView, migrations. Use when generating resources via mix ash.codegen, editing changes, checks, types, validations, or domain code interfaces." effort: medium user-invocable: false

Ash Framework Reference

Reference for Ash Framework in Phoenix/LiveView projects. Ash complements Phoenix/Ecto — LiveView, security, and OTP Iron Laws still apply. Only data access patterns shift toward Ash actions and domain code interfaces.

Iron Laws

  1. USE DOMAIN CODE INTERFACES — Never call Ash.create/Ash.read directly in LiveViews or Controllers; use domain code interfaces: MyApp.Accounts.register_user() not Ash.create(User, attrs)
  2. SET ACTOR/SCOPE AT QUERY PREP, NOT EXECUTION — Give actor: or scope: to for_read/for_create/for_action (prep), NOT to Ash.read!/Ash.create! (execution); execution-level actor bypasses row-level policy evaluation. If project uses Ash.Scope, use scope: consistently instead of bare actor: — do not mix styles
  3. GENERATORS FIRST — Before writing Ash code manually, run mix ash.gen.resource or mix ash.gen.domain with --yes; check mix help ash.gen.<task> for options
  4. CODEGEN AFTER RESOURCE CHANGES — Always run mix ash.codegen after modifying resources; this generates migrations from resource snapshots — never write AshPostgres migrations by hand
  5. ACTIONS OVER FUNCTIONS — Put business logic in named actions, not domain functions; expose via code interfaces defined on the domain
  6. NEVER EDIT RESOURCE SNAPSHOTS — priv/resource_snapshots/ is owned exclusively by mix ash.codegen; manual edits corrupt migration tracking
  7. NO DIRECT Repo.* IN ASH PROJECTS — Repo.all/get/insert bypass Ash policies and notifications; use domain code interfaces. Any Repo call in an Ash project is an escape hatch and must be documented

Quick Reference

Domain Code Interface Pattern

# Domain definition
defmodule MyApp.Accounts do
  use Ash.Domain

  resources do
    resource MyApp.Accounts.User do
      define :register_user, action: :create, args: [:email, :name]
      define :get_user_by_email, action: :read, get_by: [:email]
    end
  end
end

# In LiveView/Controller — always via domain, never Ash.create directly
{:ok, user} = MyApp.Accounts.register_user(email, name, actor: nil)
user = MyApp.Accounts.get_user_by_email!(email, actor: current_user)

Authorization — Actor/Scope at Query Prep

# CORRECT — actor at query prep, policies evaluated per-row
MyApp.Post
|> Ash.Query.for_read(:list_published, %{}, actor: current_user)
|> Ash.read!()

# CORRECT with Ash.Scope (carries actor + tenant + context; use if project adopts it)
MyApp.Post
|> Ash.Query.for_read(:list_published, %{}, scope: scope)
|> Ash.read!()

# WRONG — actor at execution bypasses row-level policy evaluation
MyApp.Post
|> Ash.Query.for_read(:list_published)
|> Ash.read!(actor: current_user)

Ash.Scope — When the Project Uses It

Ash.Scope bundles actor + tenant + context into a single struct carried through actions. Implement Ash.Scope.ToOpts on a project-defined scope struct:

defimpl Ash.Scope.ToOpts, for: MyApp.Scope do
  def get_actor(%{current_user: u}), do: {:ok, u}
  def get_tenant(%{current_tenant: t}), do: {:ok, t}
  def get_context(%{locale: l}), do: {:ok, %{shared: %{locale: l}}}
  def get_tracer(_), do: :error
  def get_authorize?(_), do: :error
end

Detection: if the project has a Scope module implementing Ash.Scope.ToOpts, use scope: everywhere instead of bare actor:. Do NOT mix the two styles in the same codebase. See mix usage_rules.docs Ash.Scope for full protocol spec.

File Conventions (from mix ash.gen.*)

| File | Location | Behaviour | | -------------- | --------------------------------- | ----------------------------- | | Changes | lib/app/ctx/changes/name.ex | use Ash.Resource.Change | | Policy Checks | lib/app/ctx/checks/name.ex | use Ash.Policy.Check | | Custom Actions | lib/app/ctx/actions/name.ex | generic action logic | | Custom Types | lib/app/ctx/types/name.ex | use Ash.Type | | Validations | lib/app/ctx/validations/name.ex | use Ash.Resource.Validation |

Generator Workflow

mix ash.gen.resource MyApp.Accounts.User --yes
mix ash.gen.domain MyApp.Accounts --yes
mix ash.codegen        # reads resource snapshots → generates migration
mix ash.migrate

Research

Prefer the highest-fidelity source available:

  1. Tidewave (exact version from mix.lock):

    mcp__tidewave__get_docs(module: "Ash.Resource")
    mcp__tidewave__get_docs(module: "AshPhoenix.Form")
    
  2. usage_rules (project-synced to your installed ash_* dep versions):

    mix usage_rules.search_docs "<topic>" -p ash -p ash_phoenix -p ash_postgres -p ash_authentication -p ash_oban
    mix usage_rules.docs Ash.Resource
    
  3. WebFetch hexdocs.pm (fallback when neither is available):

    WebFetch(url: "https://hexdocs.pm/ash/Ash.Resource.html", prompt: "Extract module docs.")
    

If usage_rules is not configured, the SessionStart hook suggests how to install it.

Related Skills

View on GitHub
GitHub Stars560
CategorySecurity
Updated3d ago
Forks44

Languages

Python

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions