Agent skill

Oma Backend

by first-fluke in first-fluke/oh-my-agent

Implement server APIs, authentication, and application data access.

MITAuto-check passedBackend & APIs

Install Oma Backend

skills CLI
$ npx skills add first-fluke/oh-my-agent --skill oma-backend -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install first-fluke/oh-my-agent oma-backend --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/first-fluke/oh-my-agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/oma-backend .claude/skills/oma-backend && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
oma-backend
GitHub stars
1.3k
Token cost
~2.6k tokens
SKILL.md length
1,152 words
Files
18
Skills in repo
57
Repo updated
First seen
Licence
MIT

At a glance

Implement server APIs, authentication, and application data access.

  • Works in 3 steps: Detect the backend stack from project… → Identify affected router, service,… → Load stack-specific references only when…
  • Tasks that involve Query optimization
  • SKILL.md covers Scheduling, Structural Flow and Logical Operations
  • Runs TypeScript, Python and Rust scripts from its folder

What it does

Oma Backend is an agent skill from first-fluke/oh-my-agent. Implement server APIs, authentication, and application data access. Schema modeling and query tuning use oma-db.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 22 other files (for example `resources/checklist.md`, `resources/error-playbook.md` and `resources/execution-protocol.md`).

It sits in Backend & APIs, covering Query optimization and Authentication. The repository describes itself as: Mechanical verification for AI coding agents — skills pack or full harness (stop-hook gates, artifact checks, independent judges). The licence is MIT.

When your agent uses it

  • Tasks that involve Query optimization
  • Tasks that involve Authentication

Example prompts

  • “/oma-backend”

Requirements

  • Python 3
  • Node.js

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Detect the backend stack from project files first.
  2. Identify affected router, service, repository, model, migration, and test boundaries.
  3. Load stack-specific references only when needed.

What it can do on your machine

Read from SKILL.md and the folder at commit b364119. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript, Python and Rust, from the files we listed), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Oma Backend loads about 2.6k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 1,152 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from first-fluke/oh-my-agent at commit b364119, republished under its MIT licence (© first-fluke). 1,152 words, ~2,553 tokens.

Download SKILL.mdSave it as .claude/skills/oma-backend/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.
name
oma-backend
description
Implement server APIs, authentication, and application data access. Schema modeling and query tuning use oma-db.

Backend Agent - API & Server Specialist

Scheduling

Goal

Implement or review backend APIs, authentication, database integration, server-side business logic, and migrations using the project's existing backend stack and clean architecture boundaries.

Intent signature
  • User asks for API, endpoint, REST, GraphQL, auth, server, migration, repository, service, router, or background job work.
  • User needs backend code that coordinates validation, business logic, persistence, transactions, and backing services.
When to use
  • Building REST APIs or GraphQL endpoints
  • Database design and migrations
  • Authentication and authorization
  • Server-side business logic
  • Background jobs and queues
When NOT to use
  • Frontend UI -> use Frontend Agent
  • Mobile-specific code -> use Mobile Agent
Expected inputs
  • Target feature, endpoint, migration, auth flow, or server behavior
  • Existing backend stack files such as manifests, routes, services, models, and database config
  • API contracts, schemas, validation rules, and persistence requirements
  • Required verification commands or project conventions
Expected outputs
  • Backend code changes in router, service, repository, model, migration, or test files
  • Validated inputs, safe queries, transaction boundaries, and error handling
  • Verification results from the execution checklist
Dependencies
  • Project stack manifests and existing backend conventions
  • resources/execution-protocol.md, resources/checklist.md, and resources/orm-reference.md
<!-- oma-docs:ignore-start -->
  • Optional stack/stack.yaml, stack/tech-stack.md, snippets, and API templates
<!-- oma-docs:ignore-end -->
  • Database, queue, cache, mail, auth, or external API resources configured through environment or secret managers
Control-flow features
  • Branches by detected stack, ORM/query pattern, auth requirement, migration impact, and transaction scope
  • Reads and writes codebase files
  • May touch local database migrations or generated code
  • Must not hardcode secrets or share unsafe ORM lifecycle objects across concurrent work

Structural Flow

Entry
  1. Detect the backend stack from project files first.
  2. Identify affected router, service, repository, model, migration, and test boundaries.
  3. Load stack-specific references only when needed.
Scenes
  1. PREPARE: Determine stack, architecture boundaries, and acceptance criteria.
  2. ACQUIRE: Read existing routes, services, repositories, models, schemas, and config.
  3. ACT: Implement backend changes with validation, business logic, persistence, and tests.
  4. VERIFY: Run relevant lint, type, test, migration, and checklist commands.
  5. FINALIZE: Report changed behavior, verification, and unresolved risks.
Transitions
  • If stack files exist, follow them before generic guidance.
  • If ORM performance, relationship loading, transactions, or N+1 risk appears, use resources/orm-reference.md.
  • If database schema impact is primary and API work is secondary, coordinate with oma-db.
  • If auth server setup touches DB adapters or server libraries, keep it in backend scope.
Failure and recovery
  • If stack cannot be determined, ask the user or suggest running /stack-set.
  • If verification fails, fix root cause before handoff.
  • If required secrets or services are unavailable, document the blocker and keep code configurable.
Exit
  • Success: backend change is implemented, tested, and aligned with local architecture.
  • Partial success: blocker, missing dependency, or verification gap is explicit.

Logical Operations

Actions
ActionSSL primitiveEvidence
Detect stack and conventionsREADManifests, stack files, existing code
Select implementation boundarySELECTRouter/service/repository pattern
Validate inputs and schemasVALIDATEStack validation library
Implement business logicWRITEService layer code
Implement persistenceWRITERepository/model/migration code
Call external/backing servicesCALL_TOOLDB, queue, cache, auth, or API clients
Run verificationCALL_TOOLTests, typecheck, lint, migrations
Report resultNOTIFYFinal summary
Tools and instruments
  • Project language/framework toolchain
  • ORM or database client
  • Test, lint, typecheck, and migration commands
  • Stack-specific templates and snippets when present
Canonical workflow path

Use the configured code-intelligence provider to locate files and inspect symbols or content. For Serena, use find_file, search_for_pattern, get_symbols_overview, and find_symbol. Native search is limited to the provider exclusions and non-code paths permitted by the project's search policy.

<!-- oma-docs:ignore-start -->

Then run the project's discovered verification commands, usually lint/typecheck/tests and migrations when schema changes are involved. Prefer stack/stack.yaml verify: commands when present.

<!-- oma-docs:ignore-end -->
Resource scope
ScopeResource target
CODEBASEBackend source, tests, schemas, migrations
LOCAL_FSStack references and generated artifacts
PROCESSTest, lint, typecheck, migration commands
CREDENTIALSEnvironment-managed DB URLs, API keys, secrets
NETWORKExternal APIs or backing services when required
Preconditions
  • Target behavior and affected backend boundary are identifiable.
  • Project stack and verification commands can be inferred or are provided.
  • Required credentials remain outside source code.
Effects and side effects
  • Mutates backend source files, tests, and possibly migrations.
  • May change database schema, API behavior, auth behavior, or service contracts.
  • May require generated clients or migration artifacts.
Show full SKILL.md (474 more words)Show less
Guardrails

Apply framework, library, architecture, and data-model defaults only when the target project has no established choice. Scoped edits do not authorize a stack migration or unrelated infrastructure.

  1. DRY (Don't Repeat Yourself): Business logic in Service, data access logic in Repository
  2. SOLID:
    • Single Responsibility: Classes and functions should have one responsibility
    • Dependency Inversion: Use your framework's DI mechanism
  3. KISS: Keep it simple and clear
Architecture Pattern
Router (HTTP) → Service (Business Logic) → Repository (Data Access) → Models
Repository Layer
  • Encapsulate DB CRUD and query logic
  • No business logic, return ORM entities
Service Layer
  • Business logic, Repository composition, external API calls
  • Business decisions only here
Router Layer
  • Receive HTTP requests, input validation, call Service, return response
  • No business logic, inject Service via DI
Core Rules
  1. Clean architecture: router → service → repository → models
  2. No business logic in route handlers
  3. All inputs validated with your stack's validation library
  4. Parameterized queries only (never string interpolation)
  5. JWT + Argon2id for auth (bcrypt acceptable for legacy compatibility); rate limit auth endpoints
  6. Async where supported; type annotations on all signatures
  7. Custom exceptions via centralized error module (not raw HTTP exceptions)
  8. Explicit ORM loading strategy: do not rely on default relation loading when query shape matters
  9. Explicit transaction boundaries: group one business operation into one request/service-scoped unit of work
  10. Safe ORM lifecycle: do not share mutable ORM session/entity manager/client objects across concurrent work unless the ORM explicitly supports it
  11. Validate required configuration: DB URLs, API keys, secrets, and feature flags come from environment variables or secret managers. Missing credentials fail clearly in default and production modes. Deterministic fixtures require an explicitly selected test/demo mode; label simulated results and never treat simulated payment, authentication, mail, or other effects as completed real operations.
  12. Stateless services: no in-memory session or user state between requests; use external stores (DB, Redis, cache) for shared state
  13. Backing services as resources: DB, queue, cache, mail are swappable attached resources connected via config; Repository layer must not assume a specific instance
Stack Detection
  1. Project files first: Read existing code, package manifests (pyproject.toml, package.json, Cargo.toml, go.mod, pom.xml, etc.) to determine the tech stack
  2. stack/ second: If stack/ exists, use it as supplementary reference for coding conventions and snippet templates
  3. Neither exists: Ask the user or suggest running /stack-set
Stack-Specific Reference
<!-- oma-docs:ignore-start -->
  • Stack manifest (SSOT): stack/stack.yaml: structured declaration (language, framework, orm) and verify: contract consumed by oma verify agent backend. Schema: variants/stack.schema.json.
  • Tech stack narrative: stack/tech-stack.md: human-readable reference only; stack.yaml wins on conflict.
  • Code snippets (copy-paste ready): stack/snippets.md
  • API template: stack/api-template.*
<!-- oma-docs:ignore-end -->

References

  • Local code tools: ../_shared/core/code-intelligence.md (code search/navigation)

  • Execution steps (follow for the selected task): resources/execution-protocol.md

  • Checklist (run before handoff): resources/checklist.md

  • ORM reference: resources/orm-reference.md

  • Error recovery: resources/error-playbook.md

  • Context loading: ../_shared/core/context-loading.md

  • Clarification: ../_shared/core/clarification-protocol.md

  • Context budget: ../_shared/core/context-budget.md

  • Lessons learned: ../_shared/core/lessons-learned.md (matching prior failure or requested retrospective)

  • Observability handoff: ../oma-observability/SKILL.md §Integrations — propagators/baggage, span conventions, log correlation, PII redaction

© first-fluke, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 17 other files in skills/oma-backend of first-fluke/oh-my-agent.

  • SKILL.md
  • resources/checklist.md
  • resources/error-playbook.md
  • resources/execution-protocol.md
  • resources/orm-reference.md
  • variants/node/api-template.ts
  • variants/node/snippets.md
  • variants/node/stack.yaml
  • variants/node/tech-stack.md
  • variants/python/api-template.py
  • variants/python/snippets.md
  • variants/python/stack.yaml
  • variants/python/tech-stack.md
  • variants/rust/api-template.rs
  • variants/rust/snippets.md
  • variants/rust/stack.yaml
  • … and 2 more

Open the folder on GitHubat commit b364119

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in first-fluke/oh-my-agent, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Oma Backend next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Oma Backend compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Oma Backend this skillfirst-fluke/oh-my-agent1.3k—~2.6kAutomated safety check: PassMIT
Querying Production Databases Via MetabasePostHog/posthog40k—~2.8kAutomated safety check: PassCustom licence
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT
Wp Performancegambitph/Stackable3513 repos~1.5kAutomated safety check: PassGPL-3.0
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT

Similar skills

  • Runs read-only production database analysis through PostHog's internal Metabase instances.

    40k GitHub stars~2.8k tokensUpdated today
    DatabasesAuto-check passed
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Wp Performance

    gambitph/Stackable

    A skill your agent uses when investigating or improving WordPress performance (backend-only agent): profiling and measurement (WP-CLI profile/doctor, Server-Timing, Query Monitor via REST headers)…

    351 GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Ecto Persistence Patterns

    georgeguimaraes/elixir-agent-tools

    Designs and debugs Elixir persistence with Ecto: schemas, changesets, queries, preloads, migrations and multi-tenancy, kept within application contexts.

    184 GitHub stars~1.2k tokensUpdated 20 days ago
    Backend & APIsAuto-check passed

More from first-fluke/oh-my-agent

All 57 skills in this repo
  • OMA Multi-Agent Orchestration

    first-fluke/oh-my-agent

    Decomposes a complex feature into tasks, dispatches parallel specialist agents with durable state, and supervises verification, QA review and retries.

    1.3k GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • OMA Multi-Agent Orchestrator

    first-fluke/oh-my-agent

    Splits a complex feature into prioritized tasks, spawns specialist CLI subagents in parallel, tracks them through shared memory and verifies each result.

    1.3k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Architecture Decisions and ADRs

    first-fluke/oh-my-agent

    Evaluates system boundaries and tradeoffs and writes architecture recommendations, option comparisons or ADRs, with a Mermaid diagram when structure changes.

    1.3k GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • OMA Backend Agent

    first-fluke/oh-my-agent

    Backend specialist for APIs, database work, authentication and migrations that follows clean architecture with router, service and repository layers.

    1.3k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • oma Bootstrap

    first-fluke/oh-my-agent

    Installs or checks the oma CLI and its runtimes (bun, uv, serena) in a fresh workspace so that oma-* skills can run their commands.

    1.3k GitHub stars~719 tokensUpdated today
    Auto-check passed
  • Design-First Brainstorm

    first-fluke/oh-my-agent

    Explores intent, constraints and alternative approaches before any planning, working through questions one at a time and saving an approved design for later steps.

    1.3k GitHub stars~1.7k tokensUpdated today
    Auto-check passed

Questions about Oma Backend

What does Oma Backend do?

Implement server APIs, authentication, and application data access. Oma Backend is an agent skill from first-fluke/oh-my-agent. Implement server APIs, authentication, and application data access.

When should I use Oma Backend?

Oma Backend fits situations like: tasks that involve Query optimization; tasks that involve Authentication.

How do I install Oma Backend in Claude Code?

Run `npx skills add first-fluke/oh-my-agent --skill oma-backend -a claude-code`. Or copy the skill folder (skills/oma-backend in first-fluke/oh-my-agent) into .claude/skills/oma-backend in your project. Claude Code loads it when a task matches its description.

How do I install Oma Backend in Codex?

Run `npx skills add first-fluke/oh-my-agent --skill oma-backend -a codex`. Or copy the skill folder (skills/oma-backend in first-fluke/oh-my-agent) into .agents/skills/oma-backend in your project. Codex loads it when a task matches its description.

Can I use Oma Backend in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add first-fluke/oh-my-agent --skill oma-backend -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/oma-backend, .gemini/skills/oma-backend, .github/skills/oma-backend and .opencode/skills/oma-backend in your project.

What does Oma Backend need to run?

Going by SKILL.md and its folder, Oma Backend needs TypeScript, Python and Rust for the scripts in its folder. Our summary lists: Python 3; Node.js.

Does Oma Backend access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Oma Backend safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Oma Backend use?

Oma Backend is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Oma Backend use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Oma Backend?

Skills that share tags, products or a category with Oma Backend: Querying Production Databases Via Metabase (PostHog/posthog, 40k stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Better Auth Best Practices (latitude-dev/latitude-llm, 4.7k stars) and Wp Performance (gambitph/Stackable, 351 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Oma Backend?

first-fluke (a GitHub organization) maintains it in first-fluke/oh-my-agent, which has 1,338 GitHub stars. The repository holds 57 skills in this directory. The repository was last updated on October 9, 2026.

Source: first-fluke/oh-my-agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.