ash-framework
Ash Framework — resources, actions, policies, aggregates, calculations, AshPhoenix.Form, LiveView, migrations
Install / Use
npx skills add oliver-kriska/claude-elixir-phoenix --skill ash-frameworkInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of ash-framework
ash-framework scores 84/100 on our quality scale, 819th of 1,120 Security skills we index.
Its SKILL.md is 5.3 KB long, well organised into 14 sections with 4 code examples: a solid amount of guidance for an agent.
It has 560 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 3 days ago, so ash-framework is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
ash-framework compared with similar skills
All 4 of these similar skills score higher than ash-framework; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| ash-framework (this skill)by oliver-kriska | 84 | 560 | 3d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 13d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 13d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 14d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 14d ago | SKILL.md |
Frequently asked questions
- How do I install ash-framework?
- Run
npx skills add oliver-kriska/claude-elixir-phoenix --skill ash-framework. The install tabs above show the steps for each supported agent. - Which AI agents does ash-framework work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is ash-framework safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is ash-framework still maintained?
- The repository was last updated 3 days ago, so ash-framework is actively maintained.
Skill content
View source on GitHubname: ash-framework description: "Ash Framework — resources, actions, policies, aggregates, calculations, AshPhoenix.Form, LiveView, migrations. Use when generating resources via mix ash.codegen, editing changes, checks, types, validations, or domain code interfaces." effort: medium user-invocable: false
Ash Framework Reference
Reference for Ash Framework in Phoenix/LiveView projects. Ash complements Phoenix/Ecto — LiveView, security, and OTP Iron Laws still apply. Only data access patterns shift toward Ash actions and domain code interfaces.
Iron Laws
- USE DOMAIN CODE INTERFACES — Never call
Ash.create/Ash.readdirectly in LiveViews or Controllers; use domain code interfaces:MyApp.Accounts.register_user()notAsh.create(User, attrs) - SET ACTOR/SCOPE AT QUERY PREP, NOT EXECUTION — Give
actor:orscope:tofor_read/for_create/for_action(prep), NOT toAsh.read!/Ash.create!(execution); execution-level actor bypasses row-level policy evaluation. If project usesAsh.Scope, usescope:consistently instead of bareactor:— do not mix styles - GENERATORS FIRST — Before writing Ash code manually, run
mix ash.gen.resourceormix ash.gen.domainwith--yes; checkmix help ash.gen.<task>for options - CODEGEN AFTER RESOURCE CHANGES — Always run
mix ash.codegenafter modifying resources; this generates migrations from resource snapshots — never write AshPostgres migrations by hand - ACTIONS OVER FUNCTIONS — Put business logic in named actions, not domain functions; expose via code interfaces defined on the domain
- NEVER EDIT RESOURCE SNAPSHOTS —
priv/resource_snapshots/is owned exclusively bymix ash.codegen; manual edits corrupt migration tracking - NO DIRECT
Repo.*IN ASH PROJECTS —Repo.all/get/insertbypass Ash policies and notifications; use domain code interfaces. AnyRepocall in an Ash project is an escape hatch and must be documented
Quick Reference
Domain Code Interface Pattern
# Domain definition
defmodule MyApp.Accounts do
use Ash.Domain
resources do
resource MyApp.Accounts.User do
define :register_user, action: :create, args: [:email, :name]
define :get_user_by_email, action: :read, get_by: [:email]
end
end
end
# In LiveView/Controller — always via domain, never Ash.create directly
{:ok, user} = MyApp.Accounts.register_user(email, name, actor: nil)
user = MyApp.Accounts.get_user_by_email!(email, actor: current_user)
Authorization — Actor/Scope at Query Prep
# CORRECT — actor at query prep, policies evaluated per-row
MyApp.Post
|> Ash.Query.for_read(:list_published, %{}, actor: current_user)
|> Ash.read!()
# CORRECT with Ash.Scope (carries actor + tenant + context; use if project adopts it)
MyApp.Post
|> Ash.Query.for_read(:list_published, %{}, scope: scope)
|> Ash.read!()
# WRONG — actor at execution bypasses row-level policy evaluation
MyApp.Post
|> Ash.Query.for_read(:list_published)
|> Ash.read!(actor: current_user)
Ash.Scope — When the Project Uses It
Ash.Scope bundles actor + tenant + context into a single struct carried through actions.
Implement Ash.Scope.ToOpts on a project-defined scope struct:
defimpl Ash.Scope.ToOpts, for: MyApp.Scope do
def get_actor(%{current_user: u}), do: {:ok, u}
def get_tenant(%{current_tenant: t}), do: {:ok, t}
def get_context(%{locale: l}), do: {:ok, %{shared: %{locale: l}}}
def get_tracer(_), do: :error
def get_authorize?(_), do: :error
end
Detection: if the project has a Scope module implementing Ash.Scope.ToOpts, use
scope: everywhere instead of bare actor:. Do NOT mix the two styles in the same codebase.
See mix usage_rules.docs Ash.Scope for full protocol spec.
File Conventions (from mix ash.gen.*)
| File | Location | Behaviour |
| -------------- | --------------------------------- | ----------------------------- |
| Changes | lib/app/ctx/changes/name.ex | use Ash.Resource.Change |
| Policy Checks | lib/app/ctx/checks/name.ex | use Ash.Policy.Check |
| Custom Actions | lib/app/ctx/actions/name.ex | generic action logic |
| Custom Types | lib/app/ctx/types/name.ex | use Ash.Type |
| Validations | lib/app/ctx/validations/name.ex | use Ash.Resource.Validation |
Generator Workflow
mix ash.gen.resource MyApp.Accounts.User --yes
mix ash.gen.domain MyApp.Accounts --yes
mix ash.codegen # reads resource snapshots → generates migration
mix ash.migrate
Research
Prefer the highest-fidelity source available:
-
Tidewave (exact version from
mix.lock):mcp__tidewave__get_docs(module: "Ash.Resource") mcp__tidewave__get_docs(module: "AshPhoenix.Form") -
usage_rules (project-synced to your installed ash_* dep versions):
mix usage_rules.search_docs "<topic>" -p ash -p ash_phoenix -p ash_postgres -p ash_authentication -p ash_oban mix usage_rules.docs Ash.Resource -
WebFetch hexdocs.pm (fallback when neither is available):
WebFetch(url: "https://hexdocs.pm/ash/Ash.Resource.html", prompt: "Extract module docs.")
If usage_rules is not configured, the SessionStart hook suggests how to install it.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
