Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Senior Fullstack

ASecurity

Senior fullstack perspective: end-to-end feature ownership, API/UI contracts, data flow across the stack, and pragmatic stack choices. Use when building features spanning frontend and backend or reviewing fullstack code.

2 stars
0 votes
1 copies
3 views
Added 9/29/2026
ai-agentsrustgodebuggingapidatabasefrontendbackendfullstack

Works with

cliapi

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add aicodedecode/awesome-muse-skills --skill senior-fullstack --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Senior Fullstack?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Senior Fullstack
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-senior-fullstack/badge)](https://www.skillsdirectory.com/skills/aicodedecode-senior-fullstack)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: senior-fullstack
description: Senior fullstack perspective: end-to-end feature ownership, API/UI contracts, data flow across the stack, and pragmatic stack choices. Use when building features spanning frontend and backend or reviewing fullstack code.
category: development
---

# Senior Fullstack Engineer

## Overview

A senior fullstack engineer owns features **end to end**: from the database row to the pixel, from
the API contract to the loading state. The superpower isn't knowing two stacks — it's seeing the
whole request path at once and putting each piece of logic where it belongs, so neither side
compensates for the other's shortcuts.

This skill captures that end-to-end discipline: contract-first development, pushing logic to the
right layer, and keeping the seam between client and server clean as the product grows.

## When to use

- Building a feature that spans UI, API, and database.
- Reviewing fullstack code for layering violations or duplicated logic.
- Choosing a stack or deciding what runs where (client vs server vs edge).
- Debugging issues that cross the client/server boundary (stale data, auth, CORS, caching).
- Simplifying a codebase where frontend and backend have drifted apart.

## Core concepts

- **Contract first.** The API shape is the handshake between your two halves. Define it (types,
  errors, pagination, auth) before building either side — and generate shared types from one source
  of truth (OpenAPI, tRPC, GraphQL codegen) so the contract can't silently drift.
- **Logic placement rule.** Put logic where its data lives: validation of shape on both sides
  (client for UX, server for trust), business rules and authorization on the server, presentation
  logic on the client. Duplicated business logic across the seam is a bug waiting to diverge.
- **The seam is a product.** Error formats, loading semantics, retry behavior, and cache
  invalidation are part of the API's UX. A 500 with an HTML stack trace is a broken contract.
- **Minimize round trips.** Design endpoints around use cases, not tables. A screen that needs
  seven requests needs a better endpoint (or a batched query layer), not a loading-spinner orchestra.
- **Own the data lifecycle.** From migration to cache invalidation to archival: the fullstack
  engineer thinks about what happens to data a year later, not just on the happy-path POST.
- **Boring stack, sharp edges.** Prefer one well-understood stack over best-of-breed everything.
  Fullstack leverage comes from moving fast across the seam, not from exotic tooling.

## Practical workflow

1. **Sketch the user journey** as a sequence of states, then map each state to the data it needs.
2. **Write the contract.** Endpoints/operations, request/response shapes, error codes, auth
   requirements. Share the draft with "the other side" (even if that's future-you) and agree.
3. **Build server-first for the critical path**: schema migration → domain logic with tests →
   endpoint with contract tests. The UI can mock the contract while the server is built.
4. **Build the client against the contract**, implementing all four async states (loading, error,
   empty, success) and optimistic updates only where rollback is well-defined.
5. **Wire observability across the seam**: correlation IDs from client to server logs, client-side
   error reporting tied to backend traces, and metrics on the endpoints the UI actually calls.
6. **Review the full path** before shipping: run the feature with throttled network, expired auth,
   and validation failures. The seam is where assumptions die — test it directly.

Contract-first checklist:

```text
[ ] Shared types generated from one source (no hand-copied interfaces)
[ ] Error shape consistent: { code, message, details? } on every endpoint
[ ] Auth: who can call what, enforced server-side, documented
[ ] Pagination/filtering conventions identical across list endpoints
[ ] Breaking-change policy: additive only; versioned when removing
[ ] Client handles 401 (re-auth), 403 (explain), 429 (backoff), 5xx (retry/fallback)
```

## Common pitfalls

- **Frontend doing backend's job.** Business rules or price calculations in client JS that the
  server doesn't re-verify. The client is a user agent, not a trusted tier.
- **Backend doing frontend's job.** Endpoints shaped for one screen's convenience that ossify into
  unmaintainable bespoke queries. Serve use cases, but keep the domain model clean underneath.
- **Chatty APIs.** N+1 at the HTTP layer: screens firing dozens of requests. Fix with batching,
  inclusion params, or a query layer — not with faster spinners.
- **Type drift.** Hand-maintained TS interfaces copied from backend DTOs, silently diverging until
  runtime. Generate; don't transcribe.
- **Ignoring the unhappy path across the seam.** Timeouts, partial failures, and stale caches are
  integration concerns — test the feature under degraded conditions, not just green ones.
- **Two codebases, two conventions.** Different error styles, naming, and auth patterns per side.
  One team, one set of conventions, documented once.
- **Over-abstracting early.** A shared "framework" for CRUD across the stack before you have three
  real use cases. Build the third feature, then extract the pattern.

Attribution

aicodedecodeaicodedecode
View sourceSee grades on GitHubMore from aicodedecode →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →