Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Backend

ASecurity

Backend and API development for REST APIs, HTTP services, server-side business logic, databases, SQL, ORM/query builders, authentication, authorization, validation, middleware, services, repositories, external APIs, background jobs, and server-side integrations. Use when creating, modifying, debugging, or reviewing backend or API code.

2 stars
0 votes
0 copies
2 views
Added 9/19/2026
ai-agentssqltestingdebuggingapidatabasebackendsecurityperformance

Works with

cliapi

Security Analysis

A100/100

Scanned 9/19/2026

$npx -y skills add Rhay427/D.StandarDev --skill backend --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Backend?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Backend
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/rhay427-backend/badge)](https://www.skillsdirectory.com/skills/rhay427-backend)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: backend
description: Backend and API development for REST APIs, HTTP services, server-side business logic, databases, SQL, ORM/query builders, authentication, authorization, validation, middleware, services, repositories, external APIs, background jobs, and server-side integrations. Use when creating, modifying, debugging, or reviewing backend or API code.
---

# Backend and API Development Skill

Backend-specific rules for REST APIs, server logic, databases, and integrations. Global CLAUDE.md already covers general development philosophy, security baselines, and communication — this skill only adds backend-specific judgment.

## Before Making Changes

**Trivial, scoped change** (single field, validator, endpoint tweak, isolated bug fix): inspect only the directly relevant file(s), follow the existing nearby pattern, make the smallest correct change, run the smallest relevant verification. Skip architecture discovery, SDD, and subagents.

**Non-trivial change** (new endpoint, new module, cross-layer change, schema change): inspect the relevant module's controller/service/repository/data-access patterns, check for existing shared utilities/types/validators before creating new ones, understand the relevant database behavior, write a brief bullet-point plan, implement the smallest appropriate change, then verify and review the diff.

Stop exploring once you have enough information to implement safely — don't read unrelated modules or re-inspect files already read.

## Architecture

Prefer the project's existing architecture over generic backend patterns. Before adding a new controller, service, repository, DTO, validator, utility, type, constant, query, or middleware/guard/interceptor, search for an existing equivalent first and extend it if reasonable. Don't introduce an abstraction just because it's theoretically cleaner.

## API Behavior

- Follow existing endpoint, routing, and response-envelope conventions.
- Validate request bodies, path params, and query params with the project's existing validation mechanism.
- Preserve existing response shapes unless the task requires a change.
- Use HTTP status codes consistent with the rest of the API.
- Consider pagination, filtering, sorting, and rate limiting only when the endpoint's shape calls for it.

## Authentication / Authorization

- Identify the existing auth mechanism and existing guards/middleware/decorators before writing new checks; reuse the established pattern.
- Authentication proves identity, not permission — always verify authorization against the *specific* resource/action being accessed.
- Watch for IDOR and privilege-escalation paths when a handler touches user-owned or role-scoped data.

## Database

- Inspect the existing schema and query patterns before writing new ones; prefer the project's query-builder/ORM over raw SQL.
- Let the database enforce what it can. A `NOT NULL`, `UNIQUE`, `CHECK`, or foreign-key constraint holds for every writer — including future ones and manual edits — while the equivalent check in application code holds only for the path you wrote it on. Use both when the API needs a friendly error; never the application check alone for an invariant the data must always satisfy.
- Wrap multi-statement writes that must be atomic in a transaction, using the project's existing mechanism.
- Determine whether a schema change needs a migration — a schema edit without one is incomplete.
- Never run destructive or production-data-altering operations without explicit user confirmation.

## Error Handling

Follow the project's existing error/exception pattern. Never expose stack traces, raw SQL errors, or other internal details to clients — but keep client-facing messages informative enough to be actionable. Secret-handling in logs follows global CLAUDE.md.

## Performance

Only investigate when the change makes it relevant, not preemptively. Check for: unnecessary or N+1 queries, missing indexes, over-fetching, unneeded network calls, and transaction boundaries that are too broad or narrow.

## Testing and Verification

Match verification to the size of the change:

| Change | Verification |
|---|---|
| DTO/validation tweak | relevant unit test or typecheck |
| service logic | unit/integration test covering that logic |
| API endpoint | relevant API/integration test |
| database/schema change | migration check + relevant tests |
| multi-module feature | full relevant test suite + build |

Don't run the full backend suite for an isolated trivial change unless the project requires it. Only report verification as done if it was actually run.

## SDD and Subagents

Skip SDD for trivial fixes, small endpoint/validation changes, and simple maintenance — a few mental bullets is enough. Reserve a real spec/plan for features spanning multiple modules or PRs; touching more than one file isn't by itself a reason for SDD. Likewise, skip subagents for small bug fixes, DTO/validation changes, and isolated service changes; use one only when parallel investigation of a genuinely complex, multi-area problem would save real time.

Attribution

Rhay427Rhay427
View sourceSee grades on GitHubMore from Rhay427 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →