ERB Escape Audit - Rails XSS lint

15 rules that find every line in a Rails .erb view where output escaping was switched off or was the wrong escaping.
Install
npx @readystack/erb-escape-audit file
Node 18+. The same 15 rules as the VS Code extension, from a terminal or CI.
Free
- Audit the .erb file you have open: every unescaped-output line with its line number, severity and the escaping helper that fixes it - no key, no cap, no watermark.
--rules lists every rule
With a licence ($29 once)
- Sweep every .erb file in the workspace in one run and write a dated Markdown/CSV report you keep as the evidence artefact for a release note or a vulnerability-handling record.
@readystack/erb-escape-audit --dir ./templates --report html --out report.html
A freelance Rails developer doing the same template review by hand bills $75-$150 an hour.
Use from an AI agent (MCP)
Claude Code · Cursor · Windsurf · any MCP client - add to your MCP config:
{ "mcpServers": { "erb-escape-audit": { "command": "npx", "args": ["-y", "@readystack/erb-escape-audit", "--mcp"] } } }
Tools: check_text and check_file (free) · check_dir (licence). The agent gets every finding with the line number.
Use in CI
- name: ERB Escape Audit - Rails XSS lint
run: npx -y @readystack/erb-escape-audit --dir . --ci
(container: docker run --rm -v "$PWD:/work" getreadystack/erb-escape-audit --dir /work --ci)
The folder sweep, reports and CI mode need one licence — one payment, no subscription. Set READYSTACK_LICENSE=<key> or run --license <key> once.
Get a licence