Agent skill

Daoyou Backend API Security

by ChurchTao in ChurchTao/Daoyou

Daoyou NestJS API、认证、授权、Better Auth、ALTCHA、admin、internal cron、LLM header 安全和服务端输入校验指南。Use when adding or modifying apps/api/src controllers, guards, middleware, auth, admin endpoints, cron/internal…

GPL-3.0Auto-check passedProductivity & Automation

Install Daoyou Backend API Security

skills CLI
$ npx skills add ChurchTao/Daoyou --skill daoyou-backend-api-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ChurchTao/Daoyou daoyou-backend-api-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ChurchTao/Daoyou.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/daoyou-backend-api-security .claude/skills/daoyou-backend-api-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
daoyou-backend-api-security
GitHub stars
146
Token cost
~3k tokens
SKILL.md length
1,335 words
Files
2
Skills in repo
9
Repo updated
First seen
Licence
GPL-3.0

At a glance

Daoyou NestJS API、认证、授权、Better Auth、ALTCHA、admin、internal cron、LLM header 安全和服务端输入校验指南。Use when adding or modifying apps/api/src controllers, guards, middleware, auth, admin endpoints, cron/internal…

  • Works in 8 steps: Classify the endpoint: public,… → Reuse the existing guards and… → Add or reuse Zod schemas for request… → …
  • Modifying apps/api/src controllers
  • SKILL.md covers Read First, Configuration and Workspace…, API Boundary Facts and LLM Security Facts, plus 5 more sections
  • Needs CRON_SECRET

What it does

Daoyou Backend API Security is an agent skill from ChurchTao/Daoyou. Daoyou NestJS API、认证、授权、Better Auth、ALTCHA、admin、internal cron、LLM header 安全和服务端输入校验指南。Use when adding or modifying apps/api/src controllers, guards, middleware, auth, admin endpoints, cron/internal endpoints, shared contracts, LLM provider handling, API validation, or security-relevant frontend auth/admin loaders in this repo. Does not cover ordinary page styling or navigation.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Productivity & Automation, covering Scheduled and recurring tasks. It works with Better Auth, NestJS and Hono. The repository describes itself as: 《万界道友》是一款以 AIGC 驱动、高自由度文字体验、修仙世界观为核心的开源游戏。在这里,你将以普通修士之身,借功法、灵根、神通、法宝与奇遇,一步步推演自己的修行之路。 The licence is GPL-3.0.

When your agent uses it

  • Modifying apps/api/src controllers
  • Admin endpoints
  • Cron/internal endpoints
  • Shared contracts

Example prompts

  • “/daoyou-backend-api-security”

Requirements

  • Node.js
  • A credential in CRON_SECRET

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Classify the endpoint: public, logged-in, active-cultivator, admin, or internal cron.
  2. Reuse the existing guards and SessionService. Do not hand-roll session parsing.
  3. Add or reuse Zod schemas for request bodies and query strings.
  4. Register controllers in feature modules imported by apps/api/src/app.module.ts; internal jobs belong to the runtime module and shared job…
  5. If the route changes a request/response shape, update its owner in packages/contracts/src; domain models belong to packages/game-domain/src.
  6. If the route calls LLM or consumes LLM output, check prompt/schema bounds and service-layer guards.
  7. If adding a prompt scene, update prompt id, LlmSceneId, caller sceneId, and schema/constraint together.
  8. Verify server behavior with lint/build, code inspection, and focused manual/runtime checks; do not add route/service/provider tests.

What it can do on your machine

Read from SKILL.md and the folder at commit 56d80d0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CRON_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Daoyou Backend API Security loads about 3k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 1,335 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ChurchTao/Daoyou at commit 56d80d0, republished under its GPL-3.0 licence (© ChurchTao). 1,335 words, ~2,968 tokens.

Download SKILL.mdSave it as .claude/skills/daoyou-backend-api-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
daoyou-backend-api-security
description
Daoyou NestJS API、认证、授权、Better Auth、ALTCHA、admin、internal cron、LLM header 安全和服务端输入校验指南。Use when adding or modifying apps/api/src controllers, guards, middleware, auth, admin endpoints, cron/internal endpoints, shared contracts, LLM provider handling, API validation, or security-relevant frontend auth/admin loaders in this repo. Does not cover ordinary page styling or navigation.

Daoyou Backend API Security

Read First

  • apps/api/src/main.ts and app.module.ts
  • apps/api/src/config/configuration.module.ts, runtime.config.ts, and lib/config/environment.ts
  • apps/api/src/http/configure-http.ts
  • apps/api/src/runtime/internal-cron.controller.ts and internal-cron.guard.ts
  • apps/api/src/auth/access.guard.ts and session.service.ts
  • apps/api/src/lib/auth/auth.ts
  • apps/api/src/lib/auth/handler.ts
  • apps/api/src/utils/aiClient.ts
  • packages/contracts/src/llm/config.ts
  • packages/contracts/src/llm/routing.ts
  • packages/contracts/src, including LLM configuration and external provider protocols

Configuration and Workspace Boundary

  • API builds with nest build (Nest CLI 12 default tsc, NodeNext ESM); the six libraries build with tsc in dependency order and export dist JavaScript/declarations; Web builds with Vite. API lint uses Oxlint correctness rules with type-aware Promise checks; Web/packages/tools retain ESLint. API consumes explicit @daoyou/* library exports, never Web; libraries cannot import either host. The old shared workspace is removed. The migration-only package-boundary script and import restrictions are retired; package direction and declared dependencies remain architecture conventions. LLM generators and prompt rendering belong in apps/api/src/lib/generation.
  • Nest services inject AppConfigService; independent libraries read getRuntimeEnvironment(). The snapshot is validated once with Zod; dotenv discovery is disabled. Never log credential values on validation failure.
  • DatabaseModule exports the existing Drizzle client, preserving one pool and transaction propagation. Runtime closes it after request/message drain.

API Boundary Facts

  • API server is NestJS 12 on Node.js 24 with Express and native ws. Legacy Hono entrypoints, routes and dependencies have been removed; do not reintroduce a compatibility router.
  • /api/auth/* is handled by Better Auth through apps/api/src/lib/auth/handler.ts.
  • ApiExceptionFilter handles uncaught API errors; route-specific filters and Zod pipes preserve existing response contracts. Better Auth uses its raw Node handler before business body parsing.
  • Frontend route loaders are UX guards only. Backend handlers are the security boundary.
  • Resource protocol types/reducers live in @daoyou/contracts/resources. Runtime parsing imports apps/api/src/lib/resources/schemas.ts, which binds the existing complete item-grant and sect-delivery validators; preserve that composition when moving repository or resource readers. The Web binding lives in its own src/lib/resources/schemas.ts.
  • Domain-event subjects/versions/envelopes live in @daoyou/contracts/events. Runtime envelope parsing imports apps/api/src/lib/mq/domainEventSchema.ts, which binds the actual game-rules payload validators. Event data models belong to game-domain; keep NATS metadata in contracts.
  • Dev-tool request parsing uses apps/api/src/dev-tools/dev-tools-input.ts, binding contracts constructors to the current numeric limits and full reward/mail validators. The pure contracts/dev-tools-access policy accepts local non-production only; server module/service checks remain authoritative.
  • Arena HTTP/WS views use apps/api/src/combat/arena-view.ts, which wraps game-rules projections with the existing API/protocol fields and supplies the round-result decorator. Replay archive models/parsing live in game-domain/combat/replay-archive; transport subjects and delivery messages remain in contracts.
  • Existing auth boundary:
    • Global AccessGuard requires login unless @Access('public') is declared.
    • @Access('active') resolves user / activeCultivatorRef through SessionService; it does not hydrate a full cultivator or inject a DB executor.
    • @Access('admin') uses adminAccess.ts (ADMIN_USER_IDS or legacy ADMIN_EMAILS); account-admin requires configured user ID authorization.
    • JsonBody reads raw bytes in its first Pipe after guards, then passes parsed JSON to validation pipes. Keep its parameter factory synchronous: Nest 12 does not await a factory's Promise before the first Pipe. The reader does not inflate content-encoding; the business ceiling is 128 MiB and the webhook's independent limit is 256 KiB. FirstQuery reads the original URL without a 1,000-key truncation: query objects keep the first decoded key, named reads prefer a literal key over encoded aliases, and malformed UTF-8 escapes remain intact. Express query parsing is disabled; use FirstQuery for business queries. Zod pipes retain the intended 400 versus legacy-unhandled 500 behavior.
  • Inspect each admin controller's access metadata; do not assume a filename or frontend loader supplies authorization. Use explicit constructor @Inject because the API TypeScript configuration disables implicit design-type metadata. API/shared relative imports name emitted .js files; JSON imports use with { type: 'json' }. Nest CLI assets copy Markdown prompts; the registry reads them once at module initialization.
  • Keep NotFoundModule last in AppModule.imports: its fallback controllers preserve authorization for unknown paths in previously protected namespaces, after every concrete feature route. Do not broaden these fallbacks to all API or admin paths.
  • /internal/cron/* uses Authorization: Bearer ${CRON_SECRET}, not user sessions. In production, missing CRON_SECRET returns 500.

LLM Security Facts

  • Browser API calls use apiFetch from apps/web/src/lib/api/fetch.ts to add x-llm-provider, x-llm-api-key and x-llm-model headers for /api/ requests.
  • Server LLM calls should use apps/api/src/utils/aiClient.ts (generateAiText, streamAiText, generateAiObject, generateAiArray) so provider resolution, metrics, structured output, and retry behavior stay in one path.
  • Server-side LLM_PROVIDER is a route table: provider[/model][:weight],.... It covers one or many providers and one or many models. Multiple routes are sticky by user id hash on the full provider + model. BYOK request config still wins and does not enter the split. Read/parse in packages/contracts/src/llm/routing.ts; aiClient.ts only maps env and picks.
  • Server accepts request-level BYOK only when provider, API key, and model pass packages/contracts/src/llm/config.ts; partial or invalid configuration returns 400 without falling back to the server key.
  • Request provider IDs are allowlisted in packages/contracts/src/llm/config.ts; adapters/endpoints are owned by apps/api/src/lib/llm/providers.ts. Do not accept arbitrary request Base URLs.
  • LLM metrics use in-memory fallback plus Redis key admin:llm-metrics:events:v1; do not add a parallel metrics store.
  • Prompt files under apps/api/src/prompts/*.md have id: headers. New prompt scenes usually also need LlmSceneId, caller sceneId, and schema/constraint updates.
  • Treat LLM output as untrusted input. Numeric state changes need Zod bounds and service/resource-layer guards.
Show full SKILL.md (525 more words)Show less

V6 Authority and Mutation Boundaries

  • Start with apps/api/src/combat and mode-specific feature modules, packages/contracts/src/combatV6*.ts, and apps/api/src/combat/application.
  • Resolve the actor from activeCultivatorRef; derive combat attributes, equipment, manuals and beasts server-side through CombatV6BuildService.ts. Client commands do not authorize client-supplied combat units, results or rewards.
  • Preserve session ownership/participant checks, expectedRevision validation, legal-command queries and Redis CAS. Spectator and replay views must retain their existing visibility checks.
  • State changes use the owning service's mutation/occupancy guards, transaction and resource response path (CommandExecutors.ts, ResourceMutationResponse.ts, InventoryService.ts). Check mode-specific exceptions such as dungeon recovery before reusing a blanket combat lock.
  • Terminal settlement and replay archival run through apps/api/src/runtime/messaging/combatV6Messaging.ts and V6 projectors. Retain retry/idempotency semantics; do not introduce direct route settlement alongside consumers.
  • /api/battle-records/* has been removed; do not restore V5 battle handlers for new V6 history features.

External Service Facts

  • Redis access must go through apps/api/src/lib/redis; do not instantiate new Redis() in feature code.
  • Production requires REDIS_URL; readiness fails unless Redis is up. Non-production may omit Redis for limited tooling, but must not report game readiness.
  • NATS access uses apps/api/src/lib/nats; Nest RuntimeService owns shared messaging startup and shutdown. Drain handlers and pending publications before closing database/Redis. Health checks include Redis, NATS and message infrastructure.
  • Native WS upgrades bypass Express: RealtimeAdapter owns API admission, response headers and pending-handshake tracking; feature services own identity and connection quotas. Preserve individual Set-Cookie headers on both successful and rejected handshakes.
  • SMTP mail uses apps/api/src/lib/admin/smtp.ts; required env includes SMTP_HOST, SMTP_PORT, SMTP_USER, SMTP_PASS, and MAIL_FROM.

Workflow

  1. Classify the endpoint: public, logged-in, active-cultivator, admin, or internal cron.
  2. Reuse the existing guards and SessionService. Do not hand-roll session parsing.
  3. Add or reuse Zod schemas for request bodies and query strings.
  4. Register controllers in feature modules imported by apps/api/src/app.module.ts; internal jobs belong to the runtime module and shared job services. Keep repositories and pure domain logic independent of Nest.
  5. If the route changes a request/response shape, update its owner in packages/contracts/src; domain models belong to packages/game-domain/src.
  6. If the route calls LLM or consumes LLM output, check prompt/schema bounds and service-layer guards.
  7. If adding a prompt scene, update prompt id, LlmSceneId, caller sceneId, and schema/constraint together.
  8. Verify server behavior with lint/build, code inspection, and focused manual/runtime checks; do not add route/service/provider tests.

Do Not

  • Do not rely on React loaders for authorization.
  • Do not bypass apps/api/src/lib/auth/handler.ts for login, signup, reset, OTP, or ALTCHA-protected flows.
  • Do not add admin files under /api/admin without explicit admin authorization.
  • Use the validated llmConfig from request context / framework-independent AsyncLocalStorage and configured provider adapters; do not bypass the provider allowlist or introduce a client Base URL. Singleton services must not store request identity or BYOK credentials in fields.
  • Do not make public list/ranking/community endpoints private without checking frontend/product usage.
  • Do not assume packages/shared/src/api exists; protocols live under packages/contracts/src.
  • Do not bypass aiClient.ts for LLM calls.
  • Do not create feature-local Redis clients or SMTP transports.

Verify

  • Route/middleware changes: run lint/build and inspect middleware registration and responses manually.
  • Auth changes: run lint/build and manually check cookie/header behavior when relevant.
  • LLM provider changes: run lint/build and inspect allowlist/validation behavior without provider tests.
  • Cron changes: verify secret behavior for production and non-production assumptions with focused runtime checks.

© ChurchTao, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/daoyou-backend-api-security of ChurchTao/Daoyou.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 56d80d0

Compare with similar skills

Daoyou Backend API Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Daoyou Backend API Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Daoyou Backend API Security this skillChurchTao/Daoyou146—~3kAutomated safety check: PassGPL-3.0
Nestjs SchedulingHoangNguyen0403/agent-skills-standard572—~623Automated safety check: PassMIT
Observatoryjgravelle/jcodemunch-mcp2.7k—~782Automated safety check: PassCustom licence
Sentry Cloudflare SDKgetsentry/sentry-for-ai268—~5.3kAutomated safety check: PassApache-2.0
Add Backendahpxex/open-dashboard146—~3.6kAutomated safety check: PassMIT
Neonneondatabase/agent-skills100—~8.7kAutomated safety check: NotesApache-2.0

Similar skills

  • Nestjs Scheduling

    HoangNguyen0403/agent-skills-standard

    Implement distributed cron jobs with Redis-based locking and BullMQ offloading in NestJS.

    572 GitHub stars~623 tokensUpdated yesterday
    Productivity & AutomationAuto-check passed
  • Observatory

    jgravelle/jcodemunch-mcp

    Context for the jcodemunch-observatory weekly scorecard — what it tracks, the Monday 06:00 UTC cron, why scores must be pulled live rather than transcribed, the NestJS grade story, and the…

    2.7k GitHub stars~782 tokensUpdated today
    Backend & APIsAuto-check passed
  • Sentry Cloudflare SDK

    getsentry/sentry-for-ai

    Official

    Full Sentry SDK setup for Cloudflare Workers and Pages. An agent skill from getsentry/sentry-for-ai.

    268 GitHub stars~5.3k tokensUpdated yesterday
    Productivity & AutomationAuto-check passed
  • Add Backend

    ahpxex/open-dashboard

    Everything about the data layer — pick one of six ready-to-run backend templates (TanStack Start + Drizzle + better-auth, Hono + Drizzle + better-auth, Hono + Prisma + better-auth, Hono + Drizzle +…

    146 GitHub stars~3.6k tokensUpdated 3 mo ago
    DatabasesAuto-check passed
  • Neon

    neondatabase/agent-skills

    Official

    Overview of Neon, a complete set of cloud backend primitives around Lakebase Postgres: Auth, Object Storage, Functions, and the AI Gateway.

    100 GitHub stars~8.7k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Fishjam JS Server SDK

    software-mansion-labs/skills

    Node.js / TypeScript server SDK for Fishjam — backends that create rooms, mint peer tokens, listen to server notifications, and run agents.

    291 GitHub stars~1.4k tokensUpdated 12 days ago
    Backend & APIsAuto-check passed

More from ChurchTao/Daoyou

All 9 skills in this repo
  • Daoyou Game UI

    ChurchTao/Daoyou

    为本项目的主流程游戏 UI 提供抽象规范与审查方法,覆盖 GameViewportLayout 及其场景页、共享壳组件和正文交互。Use when implementing, refactoring, or reviewing scene-page structure, typography, borders, navigation, component ownership, or…

    146 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Daoyou Data Layer

    ChurchTao/Daoyou

    Daoyou Drizzle/PostgreSQL、事务、V6 角色与宗门归属、统一背包、Redis 战局和回放归档指南。Use when modifying schema, migrations, repositories, persistence mappers, resource commits or durable game models.

    146 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Daoyou Game Core Domain

    ChurchTao/Daoyou

    Daoyou combat-v6 战斗内核、规则、人物投影、宗门、道装、功法、召唤灵及共享物品规则指南。Use when modifying shared combat rules, character attributes, sect content, equipment, manuals, beasts, forging, inventory or reward domain logic.

    146 GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Daoyou Beast Design

    ChurchTao/Daoyou

    万界道友灵兽物种设计与审查规范。用于新增或调整召唤兽的境界分布、命名形态、资质成长、核心天赋、出生技能池及培养空间,或将这些设计落入配置。单纯战斗内核修复使用 daoyou-game-core-domain;本技能不负责新增传承灵印机制或立绘生成。

    146 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Daoyou Ink Portraits

    ChurchTao/Daoyou

    为万界道友生成、修改或评审写意墨像立绘,统一玩家、NPC、BOSS 与灵兽的笔墨语言,涵盖物种头像构思、局部彩墨与界面适配。用于角色和生灵立绘,不用于一般页面排版、物品 emoji 或场景山水。

    146 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Daoyou Item Preview

    ChurchTao/Daoyou

    万界道友物品预览的固定展示与接入规范。新增道具、调整预览字段/文案/层级/折叠交互,或重构 ItemSlot、ItemPreview、presentation 适配器时使用;覆盖背包及复用预览的炼器、货架等入口。纯战斗规则、掉落数值或持久化变更不单独触发。

    146 GitHub stars~983 tokensUpdated today
    Auto-check passed

Questions about Daoyou Backend API Security

What does Daoyou Backend API Security do?

Daoyou NestJS API、认证、授权、Better Auth、ALTCHA、admin、internal cron、LLM header 安全和服务端输入校验指南。Use when adding or modifying apps/api/src controllers, guards, middleware, auth, admin endpoints, cron/internal…. Daoyou Backend API Security is an agent skill from ChurchTao/Daoyou. Daoyou NestJS API、认证、授权、Better Auth、ALTCHA、admin、internal cron、LLM header 安全和服务端输入校验指南。Use when adding or modifying apps/api/src controllers, guards, middleware, auth, admin endpoints, cron/internal endpoints, shared contracts, LLM provider handling, API validation, or security-relevant frontend auth/admin loaders in this repo.

When should I use Daoyou Backend API Security?

Daoyou Backend API Security fits situations like: modifying apps/api/src controllers; admin endpoints; cron/internal endpoints; shared contracts.

How do I install Daoyou Backend API Security in Claude Code?

Run `npx skills add ChurchTao/Daoyou --skill daoyou-backend-api-security -a claude-code`. Or copy the skill folder (.agents/skills/daoyou-backend-api-security in ChurchTao/Daoyou) into .claude/skills/daoyou-backend-api-security in your project. Claude Code loads it when a task matches its description.

How do I install Daoyou Backend API Security in Codex?

Run `npx skills add ChurchTao/Daoyou --skill daoyou-backend-api-security -a codex`. Or copy the skill folder (.agents/skills/daoyou-backend-api-security in ChurchTao/Daoyou) into .agents/skills/daoyou-backend-api-security in your project. Codex loads it when a task matches its description.

Can I use Daoyou Backend API Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ChurchTao/Daoyou --skill daoyou-backend-api-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/daoyou-backend-api-security, .gemini/skills/daoyou-backend-api-security, .github/skills/daoyou-backend-api-security and .opencode/skills/daoyou-backend-api-security in your project.

What does Daoyou Backend API Security need to run?

Going by SKILL.md and its folder, Daoyou Backend API Security needs credentials named CRON_SECRET. Our summary lists: Node.js; A credential in CRON_SECRET.

Does Daoyou Backend API Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Daoyou Backend API Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Daoyou Backend API Security use?

Daoyou Backend API Security is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Daoyou Backend API Security use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Daoyou Backend API Security?

Skills that share tags, products or a category with Daoyou Backend API Security: Nestjs Scheduling (HoangNguyen0403/agent-skills-standard, 572 stars), Observatory (jgravelle/jcodemunch-mcp, 2.7k stars), Sentry Cloudflare SDK (getsentry/sentry-for-ai, 268 stars) and Add Backend (ahpxex/open-dashboard, 146 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Daoyou Backend API Security?

ChurchTao (a GitHub user) maintains it in ChurchTao/Daoyou, which has 146 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 10, 2026.

Source: ChurchTao/Daoyou on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.