Skip to content
Back to skills

Backend Systems

ASecurity

Security and architecture rules for Node.js and Firebase Cloud Functions. Use when modifying API endpoints or triggers.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
code-qualitygonodeexpressdebuggingapifrontendbackendsecurity

Works with

  • api

Security analysis

A100/100

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill backend-systems --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Backend Systems?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Backend Systems
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-backend-systems/badge)](https://www.skillsdirectory.com/skills/david-li0406-backend-systems)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: backend-systems
description: Security and architecture rules for Node.js and Firebase Cloud Functions. Use when modifying API endpoints or triggers.
---

# Backend Systems

Detailed instructions for Node.js, Express, and Firebase Cloud Functions.

## When to use this skill

- Use this when modifying `functions/src/` or `server/src/`.
- This is helpful for creating new API endpoints, HTTP triggers, or background jobs.
- Use this when debugging server logs or permission errors.

## How to use it

### 1. Security First
- **Validation**: All endpoints must validate inputs (e.g., using `zod` or explicit checks).
- **Authentication**: Check `req.user` for authentication state before proceeding.
- **Authorization**: Explicitly check roles (e.g., `user.role === 'owner'`) for admin actions.

### 2. Architecture
- **Service Layer**: Business logic belongs in `services/`, not controllers/routers.
- **Types**: Always import shared types from `src/types` to ensure frontend/backend parity.
- **Region**: All resources must be in `us-west1`.

### 3. Error Handling
- Use `console.error` for exceptions (Google Cloud Error Reporting picks this up).
- Return structured JSON errors: `{ error: string, code: string }`.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…