Spree Security
Secure a Spree deployment — Rails credentials and env-var hygiene, Devise auth (Spree v5 ships it in-core; spreeauthdevise is archived), CanCanCan authorization rules, Doorkeeper OAuth2 scopes, Storefront publishable key vs admin API key, webhook HMAC verification, OWASP Top 10 for Rails (mass assignment, CSRF, SQL injection via Ransack, XSS, IDOR through prefixed IDs), PCI scope (Spree never touches raw cards thanks to gateway tokenization), and multi-store data isolation. Use when auditing a Spree app, hardening a deploy, or addressing a security incident.
Works with: Claude Code (native) · Cursor, Codex CLI (manual)
native: this artifact type is that client's own format
Category: Security — see all ranked ›
npx tashan-cli doctor can warn about it. It is not scored and does not appear in any ranking.npx tashan-cli doctor is free and tells you everything above about your whole config. tashan Pro names the replacement — which one, and how it measures. $6/mo.- Adoption: 1 repos
- Health: abandoned
Security audit
Not scanned yet. We audit npm-published capabilities for known advisories, install-time scripts and permission surface; this one has no npm package we can resolve, or has not reached the queue.
Its own instructions
Its SKILL.md says when to use it, shows worked examples and covers setup.
Read from the capability’s own SKILL.md. This is not a grade and does not compare to the instruction-depth verdict on an MCP server — a skill has no tools to document, so that rubric does not apply to it.
You searched for one. Check the rest of your stack:
npx tashan-cli doctorReads the config already on your machine and names what is dead, deprecated or running code at install time. No account, nothing uploaded.
Pro adds the history to tashan doctor, so a run over your own config says which of yours gained an advisory, started running an install script, or lost its last maintainer — and what to move to.
- Every score since we started measuring, for any capability
- The named replacement when something you run is dying — not just that it is
tashan doctorover the config you already have, on your machine
Start a 7-day trial › Everything measured on this page stays free.
source ↗ · skill:OrcaQubits/spree-security
Everything on this page is public evidence and free. What it cannot know is whether you run this — check your whole config, free, in the browser. tashan Pro adds the series behind each row and names a replacement for anything dying.
Already running this? Check your whole config — free, in your browser, nothing installed. Or npx tashan-cli doctor locally, which sends nothing at all.
Measured 2026-08-20 · scorer s5 · how · something wrong here?