Skip to content
Back to skills

Backend Core 1

ASecurity

Language-agnostic backend patterns: API design, authentication, security, databases. Use when: designing APIs, implementing auth, securing endpoints, modeling data. Triggers: "api design", "rest api", "graphql", "authentication", "jwt", "oauth", "security", "owasp", "database schema", "migrations", "sql".

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
developmentrustgosqlgitapidatabasebackendsecurityperformance

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill backend-core-1 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Backend Core 1?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Backend Core 1
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-backend-core-1/badge)](https://www.skillsdirectory.com/skills/david-li0406-backend-core-1)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: backend-core
description: |
  Language-agnostic backend patterns: API design, authentication, security, databases.
  Use when: designing APIs, implementing auth, securing endpoints, modeling data.
  Triggers: "api design", "rest api", "graphql", "authentication", "jwt", "oauth",
  "security", "owasp", "database schema", "migrations", "sql".
tags: [backend, patterns, api, authentication, security, database]
category: development
---

# Backend Core Patterns

## Quick Reference

| Topic | When to Use | Reference |
|-------|-------------|-----------|
| API Design | REST/GraphQL/gRPC endpoints | [api-design.md](references/api-design.md) |
| Authentication | JWT, OAuth, sessions, magic links | [authentication.md](references/authentication.md) |
| Security | Input validation, OWASP, rate limiting | [security.md](references/security.md) |
| Databases | Schema design, migrations, queries | [databases.md](references/databases.md) |

## API Design Decision Tree

```
What type of API?
├─ Public API → REST + OpenAPI spec
├─ Internal microservices → gRPC (performance) or REST (simplicity)
├─ Real-time → WebSocket or SSE
└─ Complex queries → GraphQL
```

## Auth Decision Tree

```
Auth method?
├─ SPA/Mobile → JWT (access + refresh tokens)
├─ Server-rendered → Session cookies
├─ Third-party login → OAuth 2.0 / OIDC
├─ Passwordless → Magic link (email) or WebAuthn
└─ API-to-API → API keys or mTLS
```

## Security Essentials

**Always:**

- Validate all inputs at boundaries
- Use parameterized queries (never string concat SQL)
- Hash passwords with bcrypt/argon2 (cost ≥ 10)
- HTTPS everywhere, HSTS headers
- Rate limit auth endpoints

**Never:**

- Store secrets in code or git
- Trust client-side validation alone
- Log sensitive data (passwords, tokens, PII)
- Use MD5/SHA1 for passwords

## Database Patterns

```
Schema design:
├─ Start normalized (3NF)
├─ Denormalize only for proven bottlenecks
├─ Always have created_at, updated_at
├─ Use UUIDs for public IDs, integers for internal FKs
└─ Soft delete (deleted_at) for important data
```

## Anti-patterns

| Don't | Do Instead |
|-------|------------|
| N+1 queries | Eager load / batch queries |
| SELECT * | Select only needed columns |
| No indexes on WHERE/JOIN columns | Add indexes |
| Storing files in DB | Use object storage (S3, R2) |
| God objects | Bounded contexts, single responsibility |

Files in this skill

  • SKILL.md2.4 KB
  • references/api-design.md2.1 KB
  • references/authentication.md2.9 KB
  • references/databases.md3.5 KB
  • references/security.md3.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…