Install
$ agentstack add skill-camilooscargbaptista-cto-toolkit-elixir-review ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Elixir / Phoenix Code Review
When to Use
- Reviewing Elixir code (Phoenix, OTP, GenServer, LiveView)
- Evaluating fault tolerance patterns (supervision trees)
- Real-time system review (WebSocket, PubSub)
- Concurrency and scalability assessment
Review Checklist
OTP Patterns
- [ ] Supervision trees properly structured (oneforone, restforone)
- [ ] GenServers have clear purpose (not catch-all)
- [ ]
handle_infohandles unexpected messages gracefully - [ ] Timeouts configured for long-running GenServers
- [ ] Process registry used (not PID passing)
- [ ] ETS tables for read-heavy shared state
Phoenix Best Practices
- [ ] Contexts separate business logic from web layer
- [ ] Schemas define changesets with validation
- [ ] Controllers are thin (delegate to context)
- [ ] Plugs for cross-cutting concerns (auth, logging)
- [ ] Ecto queries composed (not raw SQL unless necessary)
- [ ] Background jobs via Oban (not raw Task.async)
Phoenix LiveView
- [ ]
handle_eventfunctions are small and focused - [ ]
assignused for all state (no process dictionary) - [ ]
phx-throttle/phx-debounceon frequent events - [ ] PubSub for real-time updates across users
- [ ] Dead views implement
mount/3with proper assigns - [ ]
live_redirectvspush_patchused correctly
Elixir Best Practices
- [ ] Pattern matching over if/else chains
- [ ] Pipe operator (
|>) for data transformations - [ ]
withfor multi-step operations with error handling - [ ]
@spectype specs on public functions - [ ]
@docdocumentation on public functions - [ ] Structs for domain entities (not naked maps)
- [ ] Guards for function clause selection
- [ ]
EnumandStreamused appropriately (eager vs lazy)
Concurrency
- [ ] Tasks supervised (not fire-and-forget)
- [ ] GenServer state doesn't grow unbounded
- [ ] Message queue monitored (Process.info for mailbox)
- [ ] Backpressure implemented for high-throughput
- [ ] Database connection pool sized correctly
Fault Tolerance
- [ ] "Let it crash" — supervisors restart failed processes
- [ ] Circuit breakers for external service calls
- [ ] Fallback strategies for degraded service
- [ ] Health checks for supervised processes
Output Format
## Elixir Review: [Module]
**Health Score**: X/10
### Issues | Improvements | OTP Notes
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: camilooscargbaptista
- Source: camilooscargbaptista/cto-toolkit
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.