Agent skill

Replica Backend

by Jakeschincariol in Jakeschincariol/replica-skill

Builds the backend of an app clone: auth, database migrations and access rules, payments with Stripe, email, background jobs and third-party integrations through official APIs only, plus a security…

MITAuto-check: notesBackend & APIs

Install Replica Backend

skills CLI
$ npx skills add Jakeschincariol/replica-skill --skill replica-backend -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Jakeschincariol/replica-skill replica-backend --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Jakeschincariol/replica-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/replica-backend .claude/skills/replica-backend && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
replica-backend
GitHub stars
1.2k
Token cost
~997 tokens
SKILL.md length
496 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Builds the backend of an app clone: auth, database migrations and access rules, payments with Stripe, email, background jobs and third-party integrations through official APIs only, plus a security…

  • The user says add login
  • SKILL.md covers The rules, Auth, Database and Payments, plus 4 more sections
  • Calls npm
  • Wire up the database

What it does

Replica Backend is an agent skill from Jakeschincariol/replica-skill. Builds the backend of an app clone: auth, database migrations and access rules, payments with Stripe, email, background jobs and third-party integrations through official APIs only, plus a security checklist. Use when the user says "add login", "set up auth", "wire up the database", "add payments", "connect Stripe", "add Google Calendar", "send emails", "backend for my clone", or when /replica-build is running on fake data.

Its SKILL.md is about 1000 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Security review, Test data and fixtures and Background jobs. It works with Stripe and Google Calendar. The repository describes itself as: Eleven free Claude skills that clone any app: reverse-engineer it, rebuild it, test it for bugs, then fix what its users hate. Free, MIT. The licence is MIT.

When your agent uses it

  • The user says add login
  • Wire up the database
  • Add Google Calendar
  • Backend for my clone

Example prompts

  • “add login”
  • “set up auth”
  • “wire up the database”
  • “/replica-backend”

What it can do on your machine

Read from SKILL.md and the folder at commit 77c9436. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Replica Backend loads about 997 tokens when it runs. Until then it costs about 111 tokens; SKILL.md has 496 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~997

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:24
    r Google Cloud project and puts keys in `.env.local`.
  • NoteMentions a .env fileSKILL.md:76
    - [ ] secrets only in env vars, `.env*` in `.gitignore`, nothing in client bundles

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Jakeschincariol/replica-skill at commit 77c9436, republished under its MIT licence (© Jakeschincariol). 496 words, ~997 tokens.

Download SKILL.mdSave it as .claude/skills/replica-backend/SKILL.md (or your agent's skills folder).
name
replica-backend
description
Builds the backend of an app clone: auth, database migrations and access rules, payments with Stripe, email, background jobs and third-party integrations through official APIs only, plus a security checklist. Use when the user says "add login", "set up auth", "wire up the database", "add payments", "connect Stripe", "add Google Calendar", "send emails", "backend for my clone", or when /replica-build is running on fake data.

replica-backend

Reads replica/architecture.md. Writes migrations and server code, and keeps replica/backend.md (checklist below) up to date.

The rules

  • Official, public APIs only, with the user's own keys. Never call the original app's private endpoints, never reuse its OAuth client, never proxy through it.
  • The user creates accounts and keys. Claude never signs up for services, never types a password, card or live key. The user creates the Stripe, Supabase, Resend or Google Cloud project and puts keys in .env.local. Claude writes .env.example with every variable name and no values.
  • Test mode first. Stripe test keys and test cards until replica-deploy.

Auth

  • Email sign up with verification, password reset, magic link if the original has it. OAuth (Google, Apple) with the user's own developer apps.
  • Sessions: http-only secure cookies. Sign out everywhere.
  • Roles and teams if the recon map has them: owner, admin, member, with one function that answers "can this user do this to this record".
  • Account deletion that actually deletes. Apple requires it for apps with sign up.

Database

  • Migrations from architecture.md, checked in, run by a script.
  • Access rules on every table: row level security policies on Supabase, or the authorisation function called in every query. Test it: a second user must get nothing back.
  • Seed script with realistic fake data (no real people).
  • Backups on (the host's daily backups count, check they are enabled).

Payments

  • Stripe Checkout for sign up to a plan, the Customer Portal for changes and cancelling. Do not build card forms.
  • Webhooks: verify the signature, store the event id, make every handler idempotent (Stripe retries). Handle checkout.session.completed, customer.subscription.updated, customer.subscription.deleted, invoice.payment_failed.
  • Subscription status lives in your database, updated by webhooks, read by your app. Never trust the client.
  • Cancelling is one click. Hard-to-cancel billing is a top complaint about most apps, and in many places it is illegal.
Show full SKILL.md (192 more words)Show less

Email and jobs

  • Transactional email through Resend or Postmark from your own domain. Templates written fresh.
  • Jobs for anything time-based (reminders, digests, sync, cleanup) with retries and a dead-letter log. Times in UTC, shown in the user's zone.

Integrations

For each integration in the feature matrix: the official API, the OAuth scopes needed (fewest possible), the provider's review process, rate limits. Google scopes like Calendar need Google's OAuth verification before public launch, which takes weeks. Start it early and write that in backend.md.

Security checklist

  • secrets only in env vars, .env* in .gitignore, nothing in client bundles
  • input validated on the server (zod or similar) on every route
  • authorisation checked on every read and write, tested with a second user
  • rate limits on auth, sign up, and anything that sends email or SMS
  • webhooks verify signatures
  • uploads: size and type limits, served from a separate domain or bucket
  • no user data in URLs or logs
  • dependencies audited (npm audit)
  • privacy policy lists every processor (Stripe, Resend, host, analytics)

Output

Working auth, database, payments in test mode, email and the integrations, .env.example, replica/backend.md with the checklist ticked, feature matrix rows updated. Next: /replica-test.

© Jakeschincariol, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in replica-backend of Jakeschincariol/replica-skill.

Open the folder on GitHubat commit 77c9436

Compare with similar skills

Replica Backend next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Replica Backend compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Replica Backend this skillJakeschincariol/replica-skill1.2k—~997Automated safety check: NotesMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Superloopy Backend Routingbeefiker/superloopy1111 repos~3kAutomated safety check: PassMIT
OneCLI Gatewaynanocoai/nanoclaw31k—~856Automated safety check: PassMIT
Senior Backendalirezarezvani/claude-skills28k1 repos~3.8kAutomated safety check: PassMIT
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone

Similar skills

  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Superloopy Backend Routing

    beefiker/superloopy

    Routes backend work in the Superloopy loop harness to the right reference module, covering API contracts, schema migrations, transactions, background jobs, caching and security.

    111 GitHub starsUsed in 1 repo~3k tokens
    Backend & APIsAuto-check passed
  • OneCLI Gateway

    nanocoai/nanoclaw

    Explains how to call external APIs through the OneCLI proxy, which injects stored credentials into outgoing HTTPS requests so the agent never handles keys.

    31k GitHub stars~856 tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Senior Backend

    alirezarezvani/claude-skills

    Designs and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening.

    28k GitHub starsUsed in 1 repo~3.8k tokens
    Backend & APIsAuto-check passed
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Official

    Add support for a new vendor API version to an existing Data warehouse import source, or deprecate an old one.

    40k GitHub stars~8.8k tokensUpdated today
    DatabasesAuto-check passed

More from Jakeschincariol/replica-skill

All 11 skills in this repo
  • Replica Architect

    Jakeschincariol/replica-skill

    Plans the stack, database schema and API for an app clone, from the recon map replica-recon wrote.

    1.2k GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed
  • Replica Brand

    Jakeschincariol/replica-skill

    Names and rebrands an app clone so it is the user's own: name candidates with the trademark, domain, store and handle checks to run, a new palette checked for contrast, a logo brief, a voice guide…

    1.2k GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed
  • Replica Deploy

    Jakeschincariol/replica-skill

    Ships an app clone live on the user's own domain: a preflight gate (tests green, parity must-haves done, rebrand sweep clean, listing linted, legal pages up), production database and env vars, the…

    1.2k GitHub stars~1.1k tokensUpdated 6 days ago
    Auto-check passed
  • Replica Design

    Jakeschincariol/replica-skill

    Rebuilds an app's design system for a clone: colour roles, type scale, spacing, radius, shadows and every component with its states, as design tokens plus component specs, with original assets…

    1.2k GitHub stars~994 tokensUpdated 6 days ago
    Auto-check passed
  • Replica Diff

    Jakeschincariol/replica-skill

    Compares an app clone against the original: a feature parity score from the feature matrix (weighted by must, should, could) with the missing list in build order, plus a screenshot layout diff that…

    1.2k GitHub stars~1k tokensUpdated 6 days ago
    Auto-check passed
  • Replica Entrepreneur

    Jakeschincariol/replica-skill

    Researches the app being cloned and reads what its real users say in public reviews (App Store, Google Play, G2, Capterra, Trustpilot, Reddit, Hacker News, its own feature-request board), then ranks…

    1.2k GitHub stars~1.2k tokensUpdated 6 days ago
    Auto-check passed

Questions about Replica Backend

What does Replica Backend do?

Builds the backend of an app clone: auth, database migrations and access rules, payments with Stripe, email, background jobs and third-party integrations through official APIs only, plus a security…. Replica Backend is an agent skill from Jakeschincariol/replica-skill. Builds the backend of an app clone: auth, database migrations and access rules, payments with Stripe, email, background jobs and third-party integrations through official APIs only, plus a security checklist.

When should I use Replica Backend?

Replica Backend fits situations like: the user says add login; wire up the database; add Google Calendar; backend for my clone.

How do I install Replica Backend in Claude Code?

Run `npx skills add Jakeschincariol/replica-skill --skill replica-backend -a claude-code`. Or copy the skill folder (replica-backend in Jakeschincariol/replica-skill) into .claude/skills/replica-backend in your project. Claude Code loads it when a task matches its description.

How do I install Replica Backend in Codex?

Run `npx skills add Jakeschincariol/replica-skill --skill replica-backend -a codex`. Or copy the skill folder (replica-backend in Jakeschincariol/replica-skill) into .agents/skills/replica-backend in your project. Codex loads it when a task matches its description.

Can I use Replica Backend in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Jakeschincariol/replica-skill --skill replica-backend -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/replica-backend, .gemini/skills/replica-backend, .github/skills/replica-backend and .opencode/skills/replica-backend in your project.

What does Replica Backend need to run?

Going by SKILL.md and its folder, Replica Backend needs the command-line tools its instructions call (npm).

Does Replica Backend access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Replica Backend safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Replica Backend use?

Replica Backend is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Replica Backend use?

About 997 tokens (SKILL.md is roughly 4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Replica Backend?

Skills that share tags, products or a category with Replica Backend: Supabase Development and Debugging (supabase/agent-skills, 2.7k stars), Superloopy Backend Routing (beefiker/superloopy, 111 stars), OneCLI Gateway (nanocoai/nanoclaw, 31k stars) and Senior Backend (alirezarezvani/claude-skills, 28k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Replica Backend?

Jakeschincariol (a GitHub user) maintains it in Jakeschincariol/replica-skill, which has 1,158 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on October 3, 2026.

Source: Jakeschincariol/replica-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.