Agent skill

Backend Fundamentals

by DanielPodolsky in DanielPodolsky/ownyourcode

Reviews API design, REST conventions, and backend architecture.

MITAuto-check passedBackend & APIs

Install Backend Fundamentals

skills CLI
$ npx skills add DanielPodolsky/ownyourcode --skill backend-fundamentals -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install DanielPodolsky/ownyourcode backend-fundamentals --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/DanielPodolsky/ownyourcode.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/fundamentals/backend .claude/skills/backend-fundamentals && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
backend-fundamentals
GitHub stars
290
Used in
1 other repo
Token cost
~1.1k tokens
SKILL.md length
393 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Reviews API design, REST conventions, and backend architecture.

  • Works in 4 steps: Fat Routes → No Input Validation → Wrong Status Codes → …
  • Junior builds API endpoints
  • SKILL.md covers When to Apply, Review Checklist, Common Mistakes (Anti-Patterns) and Socratic Questions, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Backend Fundamentals is an agent skill from DanielPodolsky/ownyourcode. Reviews API design, REST conventions, and backend architecture. Use when junior builds API endpoints, Express routes, middleware, controllers, or asks "is this RESTful", "check my endpoint".

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering REST APIs, API design and Backend development. The repository describes itself as: Claude Code workflow for AI-mentored development. Work efficiently with Spec-Driven Development and the 6 Gates. Built to fight cognitive offloading — for developers using AI to… The licence is MIT.

When your agent uses it

  • Junior builds API endpoints
  • Asks is this RESTful
  • Check my endpoint

Example prompts

  • “is this RESTful”
  • “check my endpoint”
  • “Use the backend-fundamentals skill to review API design, REST conventions, and backend architecture”
  • “/backend-fundamentals”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Fat Routes
  2. No Input Validation
  3. Wrong Status Codes
  4. Leaking Internal Errors

What it can do on your machine

Read from SKILL.md and the folder at commit bd1f17c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Backend Fundamentals loads about 1.1k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 393 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from DanielPodolsky/ownyourcode at commit bd1f17c, republished under its MIT licence (© DanielPodolsky). 393 words, ~1,088 tokens.

Download SKILL.mdSave it as .claude/skills/backend-fundamentals/SKILL.md (or your agent's skills folder).
name
backend-fundamentals
description
Reviews API design, REST conventions, and backend architecture. Use when junior builds API endpoints, Express routes, middleware, controllers, or asks "is this RESTful", "check my endpoint".

Backend Fundamentals Review

"APIs are contracts. Break them, and you break trust."

When to Apply

Activate this skill when reviewing:

  • API route handlers
  • Express/Fastify/Hono middleware
  • Database queries and models
  • Authentication/authorization logic
  • Server-side business logic

Review Checklist

API Design
  • RESTful: Do routes follow REST conventions? (GET for read, POST for create, etc.)
  • Naming: Are endpoints nouns, not verbs? (/users not /getUsers)
  • Versioning: Is API versioned for future changes? (/api/v1/)
  • Status Codes: Are correct HTTP status codes returned?
Separation of Concerns
  • Routes: Do routes only handle HTTP concerns (req/res)?
  • Controllers: Is business logic in controllers/services, not routes?
  • Services: Is data access abstracted from business logic?
  • Models: Are models responsible only for data shape/validation?
Error Handling
  • Try/Catch: Are async operations wrapped properly?
  • Error Responses: Are errors returned with proper status codes?
  • Logging: Are errors logged with context?
  • No Leaks: Are internal errors hidden from clients?
Security
  • Input Validation: Is ALL input validated before use?
  • Authentication: Are protected routes actually protected?
  • Authorization: Can users only access their own data?
  • Rate Limiting: Are endpoints protected from abuse?

Common Mistakes (Anti-Patterns)

1. Fat Routes
❌ app.post('/users', async (req, res) => {
     // 100 lines of validation, business logic, DB queries
   });

✅ app.post('/users', validateUser, userController.create);
2. No Input Validation
❌ const { email } = req.body;
   await db.query(`SELECT * FROM users WHERE email = '${email}'`);

✅ const { email } = validateBody(req.body, userSchema);
   await User.findByEmail(email); // parameterized
3. Wrong Status Codes
❌ res.status(200).json({ error: 'Not found' });

✅ res.status(404).json({ error: 'User not found' });
4. Leaking Internal Errors
❌ catch (error) {
     res.status(500).json({ error: error.message, stack: error.stack });
   }

✅ catch (error) {
     logger.error('User creation failed', { error, userId });
     res.status(500).json({ error: 'Something went wrong' });
   }

Socratic Questions

Ask the junior these questions instead of giving answers:

  1. Architecture: "If I wanted to switch from Express to Fastify, what would need to change?"
  2. Validation: "What happens if someone sends malformed JSON?"
  3. Auth: "How do you know this user owns this resource?"
  4. Errors: "What does the client see when the database is down?"
  5. Testing: "How would you test this endpoint in isolation?"

Show full SKILL.md (134 more words)Show less

HTTP Status Code Reference

CodeWhen to Use
200Success (with body)
201Created (after POST)
204Success (no content, after DELETE)
400Bad request (validation failed)
401Unauthorized (not logged in)
403Forbidden (logged in but not allowed)
404Not found
409Conflict (duplicate resource)
500Server error (hide details from client)

Architecture Layers

Request → Route → Controller → Service → Repository → Database
                     ↓
              Middleware (auth, validation, logging)
LayerResponsibility
RouteHTTP verbs, paths, middleware chain
ControllerRequest/response handling, calling services
ServiceBusiness logic, orchestration
RepositoryData access, queries

Red Flags to Call Out

FlagQuestion to Ask
SQL in route handler"Should data access be in a separate layer?"
No try/catch on async"What happens if this fails?"
req.body used directly"What if someone sends unexpected fields?"
Hardcoded secrets"How would this work in production?"
No pagination on list endpoints"What if there are 10,000 records?"

© DanielPodolsky, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/fundamentals/backend of DanielPodolsky/ownyourcode.

Open the folder on GitHubat commit bd1f17c

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in DanielPodolsky/ownyourcode, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Backend Fundamentals next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Backend Fundamentals compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Backend Fundamentals this skillDanielPodolsky/ownyourcode2901 repos~1.1kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works16218 repos~4kAutomated safety check: PassAGPL-3.0
Pangolin CRUD Endpointsfosrl/pangolin23k—~461Automated safety check: PassCustom licence
API Designselmakcby/claude-agents-skills136—~1.1kAutomated safety check: PassMIT
API DesignerJeffallan/claude-skills12k1 repos~2kAutomated safety check: PassMIT
Backend PatternshellangleZ/burn-in-cceverywhere-ralph11217 repos~3.3kAutomated safety check: PassNone

Similar skills

  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    162 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed
  • Use whenever asked to add, create, or scaffold a CRUD endpoint, router, or entity in this repo's server (create/list/get/update/delete handlers, new…

    23k GitHub stars~461 tokensUpdated today
    Backend & APIsAuto-check passed
  • API Design

    selmakcby/claude-agents-skills

    Backend API design specialist. An agent skill from selmakcby/claude-agents-skills.

    136 GitHub stars~1.1k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • Backend Patterns

    hellangleZ/burn-in-cceverywhere-ralph

    Backend architecture patterns, API design, database optimization, and server-side best practices for Node.js, Express, and Next.js API routes.

    112 GitHub starsUsed in 17 repos~3.3k tokens
    Backend & APIsAuto-check passed
  • Fastcrud

    benavlabs/fastcrud

    A skill your agent uses when building or modifying CRUD endpoints with FastCRUD (the fastcrud PyPI package) in a FastAPI project — covers FastCRUD, crudrouter, EndpointCreator, FilterConfig…

    1.6k GitHub stars~5k tokensUpdated 15 days ago
    Backend & APIsAuto-check passed

More from DanielPodolsky/ownyourcode

All 19 skills in this repo
  • Accessibility Fundamentals

    DanielPodolsky/ownyourcode

    Reviews accessibility including WCAG, ARIA, keyboard navigation.

    290 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Database Fundamentals

    DanielPodolsky/ownyourcode

    Reviews schema design, SQL queries, ORM patterns. An agent skill from DanielPodolsky/ownyourcode.

    290 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed
  • Documentation Fundamentals

    DanielPodolsky/ownyourcode

    Guides documentation standards including READMEs, JSDoc, and code comments.

    290 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Error Handling Fundamentals

    DanielPodolsky/ownyourcode

    Guides error handling for async operations and API calls. An agent skill from DanielPodolsky/ownyourcode.

    290 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Frontend Fundamentals

    DanielPodolsky/ownyourcode

    Reviews React/Vue component architecture, state, and hooks. An agent skill from DanielPodolsky/ownyourcode.

    290 GitHub starsUsed in 1 repo~874 tokens
    Auto-check passed
  • Performance Fundamentals

    DanielPodolsky/ownyourcode

    Reviews performance including N+1 queries, re-renders, scalability.

    290 GitHub starsUsed in 1 repo~1.3k tokens
    Auto-check passed

Categories

Questions about Backend Fundamentals

What does Backend Fundamentals do?

Reviews API design, REST conventions, and backend architecture. Backend Fundamentals is an agent skill from DanielPodolsky/ownyourcode. Reviews API design, REST conventions, and backend architecture.

When should I use Backend Fundamentals?

Backend Fundamentals fits situations like: junior builds API endpoints; asks is this RESTful; check my endpoint.

How do I install Backend Fundamentals in Claude Code?

Run `npx skills add DanielPodolsky/ownyourcode --skill backend-fundamentals -a claude-code`. Or copy the skill folder (.claude/skills/fundamentals/backend in DanielPodolsky/ownyourcode) into .claude/skills/backend-fundamentals in your project. Claude Code loads it when a task matches its description.

How do I install Backend Fundamentals in Codex?

Run `npx skills add DanielPodolsky/ownyourcode --skill backend-fundamentals -a codex`. Or copy the skill folder (.claude/skills/fundamentals/backend in DanielPodolsky/ownyourcode) into .agents/skills/backend-fundamentals in your project. Codex loads it when a task matches its description.

Can I use Backend Fundamentals in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DanielPodolsky/ownyourcode --skill backend-fundamentals -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/backend-fundamentals, .gemini/skills/backend-fundamentals, .github/skills/backend-fundamentals and .opencode/skills/backend-fundamentals in your project.

What does Backend Fundamentals need to run?

SKILL.md names no scripts, command-line tools or credentials: Backend Fundamentals is instructions for the agent only.

Does Backend Fundamentals access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Backend Fundamentals safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Backend Fundamentals use?

Backend Fundamentals is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Backend Fundamentals use?

About 1.1k tokens (SKILL.md is roughly 4.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Backend Fundamentals?

Skills that share tags, products or a category with Backend Fundamentals: Nodejs Backend Patterns (ever-works/ever-works, 162 stars), Pangolin CRUD Endpoints (fosrl/pangolin, 23k stars), API Design (selmakcby/claude-agents-skills, 136 stars) and API Designer (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Backend Fundamentals?

DanielPodolsky (a GitHub user) maintains it in DanielPodolsky/ownyourcode, which has 290 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on June 27, 2026.

Source: DanielPodolsky/ownyourcode on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.