Agent skill

OMA Backend Agent

by first-fluke in first-fluke/oh-my-agent

Backend specialist for APIs, database work, authentication and migrations that follows clean architecture with router, service and repository layers.

MITAuto-check passedBackend & APIs

Install OMA Backend Agent

skills CLI
$ npx skills add first-fluke/oh-my-agent --skill oma-backend -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install first-fluke/oh-my-agent oma-backend --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/benchmarks/runs/oma/.agents/skills/oma-backend .claude/skills/oma-backend && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oma-backend
GitHub stars
1.3k
Token cost
~2.4k tokens
SKILL.md length
1,071 words
Files
19
Skills in repo
57
Repo updated
First seen
Licence
MIT

At a glance

Backend specialist for APIs, database work, authentication and migrations that follows clean architecture with router, service and repository layers.

  • Works in 3 steps: Detect the backend stack from project… → Identify affected router, service,… → Load stack-specific references only when…
  • Building REST or GraphQL endpoints on an existing backend stack
  • SKILL.md covers Scheduling, Structural Flow and Logical Operations
  • Runs TypeScript, Python and Rust scripts from its folder; calls rg

What it does

The agent starts by detecting the backend stack from project files, then identifies the router, service, repository, model, migration and test boundaries a change will touch, and loads stack-specific references only when needed. It covers REST and GraphQL endpoints, database design and migrations, authentication and authorization, server-side business logic, and background jobs and queues. Frontend UI and mobile code are left to other agents.

Expected outputs are code changes across router, service, repository, model, migration and test files, with validated inputs, safe queries, transaction boundaries and error handling, plus verification results from an execution checklist. It must not hardcode secrets or share unsafe ORM lifecycle objects across concurrent work. The folder ships resources such as a checklist, an error playbook and an ORM reference, and node, python and rust variants with API templates.

When your agent uses it

  • Building REST or GraphQL endpoints on an existing backend stack
  • Designing database changes and writing migrations
  • Adding authentication or authorization to a server
  • Implementing background jobs and queues with clear transaction boundaries

Example prompts

  • “Add a POST /orders endpoint with validation, a service layer and a repository.”
  • “Write a migration that adds a deleted_at column to the users table and update the queries.”
  • “Add token-based login to the API and keep the secrets in environment variables.”
  • “Review the invoice service for missing transaction boundaries and weak error handling.”

Requirements

  • An existing backend project whose stack can be detected from its manifests

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Detect the backend stack from project files first.
  2. Identify affected router, service, repository, model, migration, and test boundaries.
  3. Load stack-specific references only when needed.

What it can do on your machine

Read from SKILL.md and the folder at commit f65bbc0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript, Python and Rust, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

OMA Backend Agent loads about 2.4k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 1,071 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from first-fluke/oh-my-agent at commit f65bbc0, republished under its MIT licence (© first-fluke). 1,071 words, ~2,411 tokens.

Download SKILL.mdSave it as .claude/skills/oma-backend/SKILL.md (or your agent's skills folder). This skill also uses 18 other files; get the full folder from GitHub.
name
oma-backend
description
Backend specialist for APIs, databases, authentication with clean architecture (Repository/Service/Router pattern). Use for API, endpoint, REST, database, server, migration, and auth work.

Backend Agent - API & Server Specialist

Scheduling

Goal

Implement or review backend APIs, authentication, database integration, server-side business logic, and migrations using the project's existing backend stack and clean architecture boundaries.

Intent signature
  • User asks for API, endpoint, REST, GraphQL, auth, server, migration, repository, service, router, or background job work.
  • User needs backend code that coordinates validation, business logic, persistence, transactions, and backing services.
When to use
  • Building REST APIs or GraphQL endpoints
  • Database design and migrations
  • Authentication and authorization
  • Server-side business logic
  • Background jobs and queues
When NOT to use
  • Frontend UI -> use Frontend Agent
  • Mobile-specific code -> use Mobile Agent
Expected inputs
  • Target feature, endpoint, migration, auth flow, or server behavior
  • Existing backend stack files such as manifests, routes, services, models, and database config
  • API contracts, schemas, validation rules, and persistence requirements
  • Required verification commands or project conventions
Expected outputs
  • Backend code changes in router, service, repository, model, migration, or test files
  • Validated inputs, safe queries, transaction boundaries, and error handling
  • Verification results from the execution checklist
Dependencies
  • Project stack manifests and existing backend conventions
  • resources/execution-protocol.md, resources/checklist.md, and resources/orm-reference.md
  • Optional stack/stack.yaml, stack/tech-stack.md, snippets, and API templates
  • Database, queue, cache, mail, auth, or external API resources configured through environment or secret managers
Control-flow features
  • Branches by detected stack, ORM/query pattern, auth requirement, migration impact, and transaction scope
  • Reads and writes codebase files
  • May touch local database migrations or generated code
  • Must not hardcode secrets or share unsafe ORM lifecycle objects across concurrent work

Structural Flow

Entry
  1. Detect the backend stack from project files first.
  2. Identify affected router, service, repository, model, migration, and test boundaries.
  3. Load stack-specific references only when needed.
Scenes
  1. PREPARE: Determine stack, architecture boundaries, and acceptance criteria.
  2. ACQUIRE: Read existing routes, services, repositories, models, schemas, and config.
  3. ACT: Implement backend changes with validation, business logic, persistence, and tests.
  4. VERIFY: Run relevant lint, type, test, migration, and checklist commands.
  5. FINALIZE: Report changed behavior, verification, and unresolved risks.
Transitions
  • If stack files exist, follow them before generic guidance.
  • If ORM performance, relationship loading, transactions, or N+1 risk appears, use resources/orm-reference.md.
  • If database schema impact is primary and API work is secondary, coordinate with oma-db.
  • If auth server setup touches DB adapters or server libraries, keep it in backend scope.
Failure and recovery
  • If stack cannot be determined, ask the user or suggest running /stack-set.
  • If verification fails, fix root cause before handoff.
  • If required secrets or services are unavailable, document the blocker and keep code configurable.
Exit
  • Success: backend change is implemented, tested, and aligned with local architecture.
  • Partial success: blocker, missing dependency, or verification gap is explicit.

Logical Operations

Actions
ActionSSL primitiveEvidence
Detect stack and conventionsREADManifests, stack files, existing code
Select implementation boundarySELECTRouter/service/repository pattern
Validate inputs and schemasVALIDATEStack validation library
Implement business logicWRITEService layer code
Implement persistenceWRITERepository/model/migration code
Call external/backing servicesCALL_TOOLDB, queue, cache, auth, or API clients
Run verificationCALL_TOOLTests, typecheck, lint, migrations
Report resultNOTIFYFinal summary
Tools and instruments
  • Project language/framework toolchain
  • ORM or database client
  • Test, lint, typecheck, and migration commands
  • Stack-specific templates and snippets when present
Canonical workflow path
bash
rg --files
rg "route|router|service|repository|model|schema|migration" .

Then run the project's discovered verification commands, usually lint/typecheck/tests and migrations when schema changes are involved. Prefer stack/stack.yaml verify: commands when present.

Resource scope
ScopeResource target
CODEBASEBackend source, tests, schemas, migrations
LOCAL_FSStack references and generated artifacts
PROCESSTest, lint, typecheck, migration commands
CREDENTIALSEnvironment-managed DB URLs, API keys, secrets
NETWORKExternal APIs or backing services when required
Preconditions
  • Target behavior and affected backend boundary are identifiable.
  • Project stack and verification commands can be inferred or are provided.
  • Required credentials remain outside source code.
Effects and side effects
  • Mutates backend source files, tests, and possibly migrations.
  • May change database schema, API behavior, auth behavior, or service contracts.
  • May require generated clients or migration artifacts.
Show full SKILL.md (429 more words)Show less
Guardrails
  1. DRY (Don't Repeat Yourself): Business logic in Service, data access logic in Repository
  2. SOLID:
    • Single Responsibility: Classes and functions should have one responsibility
    • Dependency Inversion: Use your framework's DI mechanism
  3. KISS: Keep it simple and clear
Architecture Pattern
Router (HTTP) → Service (Business Logic) → Repository (Data Access) → Models
Repository Layer
  • Encapsulate DB CRUD and query logic
  • No business logic, return ORM entities
Service Layer
  • Business logic, Repository composition, external API calls
  • Business decisions only here
Router Layer
  • Receive HTTP requests, input validation, call Service, return response
  • No business logic, inject Service via DI
Core Rules
  1. Clean architecture: router → service → repository → models
  2. No business logic in route handlers
  3. All inputs validated with your stack's validation library
  4. Parameterized queries only (never string interpolation)
  5. JWT + bcrypt for auth; rate limit auth endpoints
  6. Async where supported; type annotations on all signatures
  7. Custom exceptions via centralized error module (not raw HTTP exceptions)
  8. Explicit ORM loading strategy: do not rely on default relation loading when query shape matters
  9. Explicit transaction boundaries: group one business operation into one request/service-scoped unit of work
  10. Safe ORM lifecycle: do not share mutable ORM session/entity manager/client objects across concurrent work unless the ORM explicitly supports it
  11. Config from environment: DB URLs, API keys, secrets, and feature flags come from env vars or secret managers — never hardcode in source
  12. Stateless services: no in-memory session or user state between requests — use external stores (DB, Redis, cache) for shared state
  13. Backing services as resources: DB, queue, cache, mail are swappable attached resources connected via config — Repository layer must not assume a specific instance
Stack Detection
  1. Project files first — Read existing code, package manifests (pyproject.toml, package.json, Cargo.toml, go.mod, pom.xml, etc.) to determine the tech stack
  2. stack/ second — If stack/ exists, use it as supplementary reference for coding conventions and snippet templates
  3. Neither exists — Ask the user or suggest running /stack-set
Stack-Specific Reference
  • Stack manifest (SSOT): stack/stack.yaml — structured declaration (language, framework, orm) and verify: contract consumed by oma verify backend. Schema: variants/stack.schema.json.
  • Tech stack narrative: stack/tech-stack.md — human-readable reference only; stack.yaml wins on conflict.
  • Code snippets (copy-paste ready): stack/snippets.md
  • API template: stack/api-template.*

References

Follow resources/execution-protocol.md step by step. See resources/examples.md for input/output examples. Use resources/orm-reference.md when the task involves ORM query performance, relationship loading, transactions, session/client lifecycle, or N+1 analysis. Before submitting, run resources/checklist.md. Vendor-specific execution protocols are injected automatically by oma agent:spawn. Source files live under ../_shared/runtime/execution-protocols/{vendor}.md.

  • Execution steps: resources/execution-protocol.md
  • Code examples: resources/examples.md
  • Checklist: resources/checklist.md
  • ORM reference: resources/orm-reference.md
  • Error recovery: resources/error-playbook.md
  • Context loading: ../_shared/core/context-loading.md
  • Reasoning templates: ../_shared/core/reasoning-templates.md
  • Clarification: ../_shared/core/clarification-protocol.md
  • Context budget: ../_shared/core/context-budget.md
  • Lessons learned: ../_shared/core/lessons-learned.md

© first-fluke, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 18 other files in benchmarks/runs/oma/.agents/skills/oma-backend of first-fluke/oh-my-agent.

  • SKILL.md
  • resources/checklist.md
  • resources/error-playbook.md
  • resources/examples.md
  • resources/execution-protocol.md
  • resources/orm-reference.md
  • variants/node/api-template.ts
  • variants/node/snippets.md
  • variants/node/stack.yaml
  • variants/node/tech-stack.md
  • variants/python/api-template.py
  • variants/python/snippets.md
  • variants/python/stack.yaml
  • variants/python/tech-stack.md
  • variants/rust/api-template.rs
  • variants/rust/snippets.md
  • … and 3 more

Open the folder on GitHubat commit f65bbc0

Compare with similar skills

OMA Backend Agent next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

OMA Backend Agent compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
OMA Backend Agent this skillfirst-fluke/oh-my-agent1.3k—~2.4kAutomated safety check: PassMIT
Senior Backendalirezarezvani/claude-skills28k1 repos~3.8kAutomated safety check: PassMIT
Pii DetectorgoSprinto/compliance-skills133—~1.6kAutomated safety check: PassMIT
API Auditbriiirussell/cybersecurity-skills413—~2.8kAutomated safety check: NotesMIT
Discover APIrand/cc-polymath1811 repos~1.5kAutomated safety check: PassMIT
Domain Webfjrevoredo/mini-diarium3081 repos~1kAutomated safety check: PassMIT

Similar skills

  • Senior Backend

    alirezarezvani/claude-skills

    Designs and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening.

    28k GitHub starsUsed in 1 repo~3.8k tokens
    Backend & APIsAuto-check passed
  • Pii Detector

    goSprinto/compliance-skills

    Proactive PII add-on — augments the main response with PII guidance.

    133 GitHub stars~1.6k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Discover API

    rand/cc-polymath

    Automatically discover API design skills when working with REST APIs, GraphQL schemas, API authentication, OAuth, JWT, rate limiting, API versioning, error handling, or endpoint design.

    181 GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed
  • Domain Web

    fjrevoredo/mini-diarium

    A skill your agent uses when building web services. An agent skill from fjrevoredo/mini-diarium.

    308 GitHub starsUsed in 1 repo~1k tokens
    Backend & APIsAuto-check passed
  • API Contract Design

    rsmdt/the-startup

    REST and GraphQL API design patterns, OpenAPI/Swagger specifications, versioning strategies, and authentication patterns.

    551 GitHub stars~1.1k tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed

More from first-fluke/oh-my-agent

All 57 skills in this repo
  • OMA Multi-Agent Orchestration

    first-fluke/oh-my-agent

    Decomposes a complex feature into tasks, dispatches parallel specialist agents with durable state, and supervises verification, QA review and retries.

    1.3k GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Oma Video

    first-fluke/oh-my-agent

    Create short, explainer, or recorded-demo videos through the OMA video CLI.

    1.3k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • OMA Multi-Agent Orchestrator

    first-fluke/oh-my-agent

    Splits a complex feature into prioritized tasks, spawns specialist CLI subagents in parallel, tracks them through shared memory and verifies each result.

    1.3k GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Architecture Decisions and ADRs

    first-fluke/oh-my-agent

    Evaluates system boundaries and tradeoffs and writes architecture recommendations, option comparisons or ADRs, with a Mermaid diagram when structure changes.

    1.3k GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • oma Bootstrap

    first-fluke/oh-my-agent

    Installs or checks the oma CLI and its runtimes (bun, uv, serena) in a fresh workspace so that oma-* skills can run their commands.

    1.3k GitHub stars~719 tokensUpdated yesterday
    Auto-check passed
  • Design-First Brainstorm

    first-fluke/oh-my-agent

    Explores intent, constraints and alternative approaches before any planning, working through questions one at a time and saving an approved design for later steps.

    1.3k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about OMA Backend Agent

What does OMA Backend Agent do?

Backend specialist for APIs, database work, authentication and migrations that follows clean architecture with router, service and repository layers. The agent starts by detecting the backend stack from project files, then identifies the router, service, repository, model, migration and test boundaries a change will touch, and loads stack-specific references only when needed. It covers REST and GraphQL endpoints, database design and migrations, authentication and authorization, server-side business logic, and background jobs and queues.

When should I use OMA Backend Agent?

OMA Backend Agent fits situations like: building REST or GraphQL endpoints on an existing backend stack; designing database changes and writing migrations; adding authentication or authorization to a server; implementing background jobs and queues with clear transaction boundaries.

How do I install OMA Backend Agent in Claude Code?

Run `npx skills add first-fluke/oh-my-agent --skill oma-backend -a claude-code`. Or copy the skill folder (benchmarks/runs/oma/.agents/skills/oma-backend in first-fluke/oh-my-agent) into .claude/skills/oma-backend in your project. Claude Code loads it when a task matches its description.

How do I install OMA Backend Agent in Codex?

Run `npx skills add first-fluke/oh-my-agent --skill oma-backend -a codex`. Or copy the skill folder (benchmarks/runs/oma/.agents/skills/oma-backend in first-fluke/oh-my-agent) into .agents/skills/oma-backend in your project. Codex loads it when a task matches its description.

Can I use OMA Backend Agent in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add first-fluke/oh-my-agent --skill oma-backend -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oma-backend, .gemini/skills/oma-backend, .github/skills/oma-backend and .opencode/skills/oma-backend in your project.

What does OMA Backend Agent need to run?

Going by SKILL.md and its folder, OMA Backend Agent needs TypeScript, Python and Rust for the scripts in its folder and the command-line tools its instructions call (rg). Our summary lists: An existing backend project whose stack can be detected from its manifests.

Does OMA Backend Agent access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is OMA Backend Agent safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does OMA Backend Agent use?

OMA Backend Agent is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does OMA Backend Agent use?

About 2.4k tokens (SKILL.md is roughly 9.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to OMA Backend Agent?

Skills that share tags, products or a category with OMA Backend Agent: Senior Backend (alirezarezvani/claude-skills, 28k stars), Pii Detector (goSprinto/compliance-skills, 133 stars), API Audit (briiirussell/cybersecurity-skills, 413 stars) and Discover API (rand/cc-polymath, 181 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains OMA Backend Agent?

first-fluke (a GitHub organization) maintains it in first-fluke/oh-my-agent, which has 1,338 GitHub stars. The repository holds 57 skills in this directory. The repository was last updated on October 8, 2026.

Source: first-fluke/oh-my-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.