Backend reconnaissance — map all routes, middleware, models, dependencies, auth, and assess code quality for project takeover.

MITAuto-check: notesDevelopment

Install Spine Recon

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill spine-recon -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace spine-recon --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ai-agency/tonone/skills/spine-recon .claude/skills/spine-recon && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spine-recon
GitHub stars
2.8k
Token cost
~1k tokens
SKILL.md length
356 words
Files
2
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Backend reconnaissance — map all routes, middleware, models, dependencies, auth, and assess code quality for project takeover.

  • Works in 8 steps: Detect Environment → Map All Routes and Endpoints → Map Middleware Stack → …
  • Asked to understand this backend
  • SKILL.md covers Steps and Delivery
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Spine Recon is an agent skill from jeremylongshore/tons-of-skills-marketplace. Backend reconnaissance — map all routes, middleware, models, dependencies, auth, and assess code quality for project takeover. Use when asked to "understand this backend", "map the API", or "assess code quality".

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `.claude-plugin/plugin.json`).

It sits in Development, covering Code quality. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Asked to understand this backend
  • Assess code quality

Example prompts

  • “understand this backend”
  • “map the API”
  • “assess code quality”
  • “/spine-recon”

Requirements

  • Pre-approved tools (allowed-tools): Read, Bash, Glob, Grep, WebFetch, WebSearch, AskUserQuestion

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Detect Environment
  2. Map All Routes and Endpoints
  3. Map Middleware Stack
  4. Map Database Models
  5. Map External Dependencies
  6. Assess Auth Mechanism
  7. Assess Code Quality
  8. Present the Assessment

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash
    • Glob
    • Grep
    • WebFetch
    • WebSearch
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spine Recon loads about 1k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 356 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash, Glob, Grep, WebFetch, WebSearch, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 356 words, ~1,049 tokens.

Download SKILL.mdSave it as .claude/skills/spine-recon/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
spine-recon
description
Backend reconnaissance — map all routes, middleware, models, dependencies, auth, and assess code quality for project takeover. Use when asked to "understand this backend", "map the API", or "assess code quality".
allowed-tools
Read, Bash, Glob, Grep, WebFetch, WebSearch, AskUserQuestion
version
0.6.4
author
tonone-ai <hello@tonone.ai>
license
MIT

Backend Reconnaissance

You are Spine — the backend engineer from the Engineering Team.

Follow the output format defined in docs/output-kit.md — 40-line CLI max, box-drawing skeleton, unified severity indicators, compressed prose.

Steps

Step 0: Detect Environment
bash
ls -a

Identify the framework, language, package manager, database, and infrastructure. Read package.json, pyproject.toml, go.mod, Cargo.toml, pom.xml, or Gemfile for the full dependency list.

Step 1: Map All Routes and Endpoints

Find and read all route definitions. Build a complete endpoint map:

MethodPathAuthHandlerDescription
GET/api/usersJWTUserController.listList users
POST/api/usersJWTUserController.createCreate user

Note any undocumented endpoints, debug routes, or admin endpoints.

Step 2: Map Middleware Stack

Identify the middleware execution order:

  1. Request logging
  2. CORS
  3. Auth (JWT / API key / session)
  4. Rate limiting
  5. Body parsing / validation
  6. Route handler
  7. Error handling

Note any middleware that applies globally vs. per-route.

Step 3: Map Database Models

List all database models/tables with:

  • Fields and types
  • Relationships (foreign keys, many-to-many)
  • Indexes
  • Migrations status (up to date, pending)
Step 4: Map External Dependencies

Identify all external services the backend calls:

  • Third-party APIs (payment, email, auth providers)
  • Cloud services (S3, Pub/Sub, SQS)
  • Other internal services

For each: note the client library used, timeout configuration, and circuit breaker status.

Show full SKILL.md (151 more words)Show less
Step 5: Assess Auth Mechanism

Document:

  • Auth type (JWT, session, API key, OAuth2, mTLS)
  • Token storage and validation approach
  • Role/permission model
  • Which endpoints are public vs. protected
Step 6: Assess Code Quality

Evaluate:

  • Test coverage — are there tests? What percentage of routes are tested?
  • Code quality signals — consistent naming, clear separation of concerns, no god files
  • Tech debt hotspots — large files (>500 lines), TODOs/FIXMEs, commented-out code, complex functions
  • Error handling — consistent patterns or ad-hoc try/catch everywhere?
  • Dependency freshness — are dependencies up to date or significantly behind?
  • Documentation — API docs, README, inline comments on complex logic
Step 7: Present the Assessment

Format as:

## Backend Recon: [project name]

**Stack:** [language] + [framework] + [database]
**Routes:** [X] endpoints across [Y] resources
**Test coverage:** [estimated percentage or "none"]

### Route Map
[endpoint table from Step 1]

### Architecture
- **Auth:** [mechanism]
- **Middleware:** [stack summary]
- **Database:** [X] models, [Y] migrations
- **External deps:** [list with timeout/circuit breaker status]

### Code Quality
| Signal            | Status        | Notes                        |
|-------------------|---------------|------------------------------|
| Test coverage     | Low/Med/High  | [details]                    |
| Error handling    | Consistent/Ad-hoc | [details]                |
| Dependency health | Current/Stale | [X deps behind major versions] |
| Tech debt         | Low/Med/High  | [hotspot files]              |

### Takeover Recommendations
1. [First thing to do when taking over this codebase]
2. [Second priority]
3. [Third priority]

Map for someone inheriting the project. Factual, specific, actionable.

Delivery

If output exceeds the 40-line CLI budget, invoke /atlas-report with the full findings. The HTML report is the output. CLI is the receipt — box header, one-line verdict, top 3 findings, and the report path. Never dump analysis to CLI.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/ai-agency/tonone/skills/spine-recon of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • .claude-plugin/plugin.json

Open the folder on GitHubat commit cfae287

Compare with similar skills

Spine Recon next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spine Recon compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spine Recon this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1kAutomated safety check: NotesMIT
WooCommerce Backend Conventionswoocommerce/woocommerce11k1 repos~614Automated safety check: PassCustom licence
Modern Csharp Coding Standardssketch7/FluentlyHttpClient1213 repos~2.7kAutomated safety check: PassMIT
Performance OptimizationThibautBaissac/rails_ai_agents665—~1.2kAutomated safety check: NotesMIT
Java Coding Standardsaffaan-m/ECC277k1 repos~2.9kAutomated safety check: PassMIT
Senior Fullstackalirezarezvani/claude-skills28k1 repos~3.7kAutomated safety check: NotesMIT

Similar skills

  • WooCommerce Backend Conventions

    woocommerce/woocommerce

    Guides agents writing or changing WooCommerce backend PHP so new classes, hooks and unit tests follow the project's conventions.

    11k GitHub starsUsed in 1 repo~614 tokens
    DevelopmentAuto-check passed
  • Modern Csharp Coding Standards

    sketch7/FluentlyHttpClient

    Write modern, high-performance C code using records, pattern matching, value objects, async/await, Span<T/Memory<T, and best-practice API design patterns.

    121 GitHub starsUsed in 3 repos~2.7k tokens
    DevelopmentAuto-check passed
  • Performance Optimization

    ThibautBaissac/rails_ai_agents

    Identifies and fixes Rails performance issues including N+1 queries, slow queries, and memory problems.

    665 GitHub stars~1.2k tokensUpdated 4 mo ago
    DevelopmentAuto-check: notes
  • Java coding standards for Spring Boot and Quarkus services: naming, immutability, Optional usage, streams, exceptions, generics, CDI, reactive patterns, and project layout.

    277k GitHub starsUsed in 1 repo~2.9k tokens
    DevelopmentAuto-check passed
  • Senior Fullstack

    alirezarezvani/claude-skills

    Fullstack development toolkit with project scaffolding for Next.js, FastAPI, MERN, and Django stacks, code quality analysis with security and complexity scoring, and stack selection guidance.

    28k GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: notes
  • Java Coding Standards

    vibeeval/vibecosystem

    Java coding standards for Spring Boot services: naming, immutability, Optional usage, streams, exceptions, generics, and project layout.

    532 GitHub starsUsed in 3 repos~877 tokens
    DevelopmentAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Spine Recon

What does Spine Recon do?

Backend reconnaissance — map all routes, middleware, models, dependencies, auth, and assess code quality for project takeover. Spine Recon is an agent skill from jeremylongshore/tons-of-skills-marketplace. Backend reconnaissance — map all routes, middleware, models, dependencies, auth, and assess code quality for project takeover.

When should I use Spine Recon?

Spine Recon fits situations like: asked to understand this backend; assess code quality.

How do I install Spine Recon in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill spine-recon -a claude-code`. Or copy the skill folder (plugins/ai-agency/tonone/skills/spine-recon in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/spine-recon in your project. Claude Code loads it when a task matches its description.

How do I install Spine Recon in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill spine-recon -a codex`. Or copy the skill folder (plugins/ai-agency/tonone/skills/spine-recon in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/spine-recon in your project. Codex loads it when a task matches its description.

Can I use Spine Recon in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill spine-recon -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spine-recon, .gemini/skills/spine-recon, .github/skills/spine-recon and .opencode/skills/spine-recon in your project.

What does Spine Recon need to run?

SKILL.md names no scripts, command-line tools or credentials: Spine Recon is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Bash, Glob, Grep, WebFetch, WebSearch, AskUserQuestion.

Does Spine Recon access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Spine Recon safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Spine Recon use?

Spine Recon is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spine Recon use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Spine Recon?

Skills that share tags, products or a category with Spine Recon: WooCommerce Backend Conventions (woocommerce/woocommerce, 11k stars), Modern Csharp Coding Standards (sketch7/FluentlyHttpClient, 121 stars), Performance Optimization (ThibautBaissac/rails_ai_agents, 665 stars) and Java Coding Standards (affaan-m/ECC, 277k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spine Recon?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.