Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Backend Service Auditor

ASecurity

Audit backend services for security, reliability, performance, and operability issues. Use when reviewing APIs, microservices, workers, or backend code changes. Triggers on "audit backend", "security review", "service audit", "API audit", "check vulnerabilities", "review microservice", "backend security", "audit API", "review service".

3 stars
0 votes
0 copies
1 views
Added 9/24/2026
securitypythonrustgojavabashnodeexpressfastapispringdocker

Works with

api

Security Analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add OneDro1d/dark-factory --skill backend-service-auditor --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Backend Service Auditor?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Backend Service Auditor
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/onedro1d-backend-service-auditor/badge)](https://www.skillsdirectory.com/skills/onedro1d-backend-service-auditor)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: backend-service-auditor
description: Audit backend services for security, reliability, performance, and operability issues. Use when reviewing APIs, microservices, workers, or backend code changes. Triggers on "audit backend", "security review", "service audit", "API audit", "check vulnerabilities", "review microservice", "backend security", "audit API", "review service".
---

# Backend Service Auditor

Comprehensive auditor for backend services (APIs, workers, microservices) focusing on security, reliability, correctness, performance, data integrity, and operability. All findings are grounded in actual code and configuration.

## When to Use

- Reviewing backend code changes before merge
- Security auditing APIs or microservices
- Pre-deployment checks for critical services
- Investigating reliability or performance concerns
- Auditing authentication/authorization flows
- Reviewing data handling and integrity patterns

## Audit Workflow

On EVERY invocation, execute these steps in order:

### Step 1: Detect Stack & Service Boundaries

Identify the technology stack and architectural boundaries:

```
- Language/framework (Node/Express/Nest, Go, Python/FastAPI, Java/Spring, Rust, etc.)
- Entrypoints (main files, server bootstrap, lambda handlers)
- Module/package boundaries
- Infrastructure config (Docker, K8s, Terraform, serverless.yml)
- Shared libraries and internal packages
```

### Step 2: Scan Recent Changes

Review what has changed recently:

```bash
# Check working directory changes
git status
git diff --stat

# Review recent commits affecting backend
git log --oneline -20 --all -- "src/" "api/" "services/" "internal/"
```

Summarize:
- What behavioral changes were introduced?
- What new attack surface was added?
- What critical paths were modified?

### Step 3: Build Service Map

Create a mental model of the service:

| Component | Details |
|-----------|---------|
| **Endpoints** | REST routes, GraphQL resolvers, gRPC services |
| **Async** | Message queues, cron jobs, webhooks |
| **Data Stores** | Databases, caches, file storage |
| **External APIs** | Third-party integrations, internal services |
| **Secrets** | API keys, credentials, tokens |

### Step 4: Execute Audit Checklist

Audit touched services plus all critical paths (auth, payments, trading, user data).

See [CHECKLIST.md](CHECKLIST.md) for the complete audit checklist covering:
- Security (AuthN/AuthZ, injection, secrets, dependencies)
- Reliability & Correctness (idempotency, retries, concurrency, data integrity)
- Performance & Scalability (queries, caching, memory)
- Observability & Ops (logging, metrics, deployment)

## Output Format

Structure your audit report as follows:

### A) Scope Scanned
```
Services: [list services/modules audited]
Files reviewed: [count]
Commits analyzed: [range]
Stack: [detected technology stack]
```

### B) Service Map
```
Endpoints: [count] routes across [modules]
Data stores: [list DBs, caches]
External deps: [list integrations]
Critical paths: [auth, payments, etc.]
```

### C) Findings

Use severity levels:

| Severity | Icon | Meaning |
|----------|------|---------|
| CRITICAL | :red_circle: | Exploitable now, data breach risk |
| HIGH | :orange_circle: | Serious issue, needs immediate fix |
| MEDIUM | :yellow_circle: | Should fix soon, moderate risk |
| LOW | :white_circle: | Minor issue, fix when convenient |
| INFO | :blue_circle: | Observation, no action required |

For each finding:
```
### [SEVERITY] Title

**Location:** `path/to/file.ts:123`
**Category:** Security > Input Validation

**Issue:** [Describe the problem]

**Evidence:**
[Code snippet or proof]

**Risk:** [What could go wrong]

**Recommendation:** [How to fix]
```

### D) Summary Table

| Category | Critical | High | Medium | Low |
|----------|----------|------|--------|-----|
| Security | 0 | 1 | 2 | 1 |
| Reliability | 0 | 0 | 1 | 2 |
| Performance | 0 | 0 | 0 | 1 |
| Observability | 0 | 0 | 1 | 0 |

### E) Recommendations

Prioritized action items:
1. [Most critical fix]
2. [Second priority]
3. ...

## Quick Commands

```bash
# Check for vulnerable dependencies (Node)
npm audit

# Check for vulnerable dependencies (Python)
pip-audit

# Find hardcoded secrets
grep -rn "password\|secret\|api_key\|token" --include="*.ts" --include="*.js" --include="*.py"

# Find TODO/FIXME security notes
grep -rn "TODO.*security\|FIXME.*auth\|XXX" src/
```

## Resources

- [CHECKLIST.md](CHECKLIST.md) - Complete audit checklist
- [PATTERNS.md](PATTERNS.md) - Common vulnerability patterns by framework

Attribution

OneDro1dOneDro1d
View sourceSee grades on GitHubMore from OneDro1d →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

953190 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

953190 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

953190 votes
View all in security →