API and backend code review — REST conventions, auth, validation, error handling, pagination, rate limiting, test coverage.

MITAuto-check: notesBackend & APIs

Install Spine Review

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill spine-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace spine-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ai-agency/tonone/skills/spine-review .claude/skills/spine-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spine-review
GitHub stars
2.8k
Token cost
~1.1k tokens
SKILL.md length
475 words
Files
2
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

API and backend code review — REST conventions, auth, validation, error handling, pagination, rate limiting, test coverage.

  • Works in 9 steps: Detect Environment → Read the Codebase → Check REST Conventions → …
  • Asked to review this API
  • SKILL.md covers Steps and Delivery
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Spine Review is an agent skill from jeremylongshore/tons-of-skills-marketplace. API and backend code review — REST conventions, auth, validation, error handling, pagination, rate limiting, test coverage. Use when asked to "review this API", "code review", "review backend", or "pre-launch backend check".

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `.claude-plugin/plugin.json`).

It sits in Backend & APIs, covering Rate limiting, Test coverage and Code review. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Asked to review this API
  • Pre-launch backend check

Example prompts

  • “review this API”
  • “code review”
  • “review backend”
  • “/spine-review”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Detect Environment
  2. Read the Codebase
  3. Check REST Conventions
  4. Check Auth on All Endpoints
  5. Check Input Validation
  6. Check Error Handling
  7. Check Pagination, Rate Limiting, and Timeouts
  8. Check Test Coverage
  9. Present the Review

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash
    • Glob
    • Grep
    • WebFetch
    • WebSearch
    • Task
    • TodoWrite

    …and 1 more on the same allowed-tools line.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spine Review loads about 1.1k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 475 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 475 words, ~1,056 tokens.

Download SKILL.mdSave it as .claude/skills/spine-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
spine-review
description
API and backend code review — REST conventions, auth, validation, error handling, pagination, rate limiting, test coverage. Use when asked to "review this API", "code review", "review backend", or "pre-launch backend check".
allowed-tools
Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion
version
0.6.4
author
tonone-ai <hello@tonone.ai>
license
MIT

API and Code Review

You are Spine — the backend engineer from the Engineering Team.

Follow the output format defined in docs/output-kit.md — 40-line CLI max, box-drawing skeleton, unified severity indicators, compressed prose.

Steps

Step 0: Detect Environment
bash
ls -a

Identify the framework, project structure, test setup, and API style (REST, GraphQL, gRPC). Read package.json, pyproject.toml, go.mod, or equivalent to understand dependencies.

Step 1: Read the Codebase

Read the route definitions, middleware, models, and tests:

  • Route/controller files — all endpoint definitions
  • Middleware stack — auth, logging, error handling, rate limiting
  • Models/schemas — database models, request/response schemas
  • Test files — existing test coverage
Step 2: Check REST Conventions

For each endpoint, verify:

  • Correct HTTP methods (GET for reads, POST for creates, PUT/PATCH for updates, DELETE for deletes)
  • Plural noun resource paths (/users, not /getUser)
  • Proper status codes (201 for created, 204 for no content, 404 for not found, not 200 for everything)
  • Consistent response envelope or format
  • Idempotent operations where expected (PUT, DELETE)
  • No verbs in URLs (/users/123, not /getUser/123)
Step 3: Check Auth on All Endpoints

Verify:

  • Every endpoint has auth middleware (or is explicitly marked as public with justification)
  • Auth checks happen before business logic, not after
  • Authorization (permissions) is checked, not just authentication (identity)
  • Token validation is not hand-rolled when a library exists
  • No sensitive data in URLs or query parameters
Step 4: Check Input Validation

Verify:

  • All request bodies are validated against a schema
  • Path parameters and query parameters are validated (type, range, format)
  • Validation happens at the boundary (controller/route level), not deep in business logic
  • Validation errors return 400 with specific field-level error messages
  • No raw user input reaches database queries (SQL injection prevention)
Show full SKILL.md (205 more words)Show less
Step 5: Check Error Handling

Verify:

  • Consistent error response format across all endpoints
  • Proper HTTP status codes (400, 401, 403, 404, 409, 422, 429, 500)
  • No stack traces or internal details in production error responses
  • Unhandled exceptions are caught by global error middleware
  • Errors are logged with request ID and context
Step 6: Check Pagination, Rate Limiting, and Timeouts

Verify:

  • All list endpoints have pagination (not unbounded queries)
  • Rate limiting is configured (per-endpoint or global)
  • Timeouts are set on all external HTTP calls and database queries
  • No missing await on async operations
  • Connection pools are configured with limits
Step 7: Check Test Coverage

Verify:

  • Happy path tests exist for each endpoint
  • Error cases are tested (bad input, unauthorized, not found)
  • Edge cases: empty lists, large payloads, concurrent requests
  • Tests actually assert on response body and status code, not just "no error"
  • Integration tests exist for critical flows
Step 8: Present the Review

Format by severity:

## Backend Review

### Critical (blocks launch)
- **[issue]** in `[file:line]` — [explanation] — [fix]

### Warning (fix before scaling)
- **[issue]** in `[file:line]` — [explanation] — [fix]

### Suggestion (improve quality)
- **[issue]** in `[file:line]` — [explanation] — [fix]

### Looks Good
- [positive observation about what's done well]

Be specific — reference files, line numbers, and exact code patterns.

Delivery

If output exceeds the 40-line CLI budget, invoke /atlas-report with the full findings. The HTML report is the output. CLI is the receipt — box header, one-line verdict, top 3 findings, and the report path. Never dump analysis to CLI.

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/ai-agency/tonone/skills/spine-review of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • .claude-plugin/plugin.json

Open the folder on GitHubat commit cfae287

Compare with similar skills

Spine Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spine Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spine Review this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.1kAutomated safety check: NotesMIT
Resiliencecodewithmukesh/dotnet-claude-kit7561 repos~3.2kAutomated safety check: PassMIT
Azure Open DatasetsMicrosoftDocs/Agent-Skills776—~579Automated safety check: PassCC-BY-4.0
Evaluate PR Testsdotnet/maui23k—~2.9kAutomated safety check: PassMIT
Code Reviewpolyipseity/obsidian-terminal951—~1.6kAutomated safety check: PassAGPL-3.0
Core Components Code Reviewcore-ds/core-components137—~5.4kAutomated safety check: PassMIT

Similar skills

  • Resilience

    codewithmukesh/dotnet-claude-kit

    Resilience patterns for .NET 10 applications using Polly v8.

    756 GitHub starsUsed in 1 repo~3.2k tokens
    Backend & APIsAuto-check passed
  • Azure Open Datasets

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Open Datasets development including limits & quotas.

    776 GitHub stars~579 tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Official

    Reviews the tests added in a pull request for fix coverage, quality, edge cases and test type, and recommends lighter test types where they would do.

    23k GitHub stars~2.9k tokensUpdated yesterday
    Testing & QAAuto-check passed
  • Code Review

    polyipseity/obsidian-terminal

    A skill your agent uses when reviewing PRs, code changes, or conducting code audits in obsidian-terminal.

    951 GitHub stars~1.6k tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • Core Components Code Review

    core-ds/core-components

    Review a Pull Request or diff in the @alfalab/core-components UI library — correctness bugs, public API/breaking changes, accessibility, keyboard/focus/pointer interaction, component states…

    137 GitHub stars~5.4k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Review

    mhmzdev/the-holy-quran-app

    Review The Holy Qur'an app code against the project's own conventions — layering (UI → Bloc → Repo → DataProvider), bloc anatomy, Provider tier, configs tokens, class widgets, Hive typeId safety…

    888 GitHub stars~907 tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Questions about Spine Review

What does Spine Review do?

API and backend code review — REST conventions, auth, validation, error handling, pagination, rate limiting, test coverage. Spine Review is an agent skill from jeremylongshore/tons-of-skills-marketplace. API and backend code review — REST conventions, auth, validation, error handling, pagination, rate limiting, test coverage.

When should I use Spine Review?

Spine Review fits situations like: asked to review this API; pre-launch backend check.

How do I install Spine Review in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill spine-review -a claude-code`. Or copy the skill folder (plugins/ai-agency/tonone/skills/spine-review in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/spine-review in your project. Claude Code loads it when a task matches its description.

How do I install Spine Review in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill spine-review -a codex`. Or copy the skill folder (plugins/ai-agency/tonone/skills/spine-review in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/spine-review in your project. Codex loads it when a task matches its description.

Can I use Spine Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill spine-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spine-review, .gemini/skills/spine-review, .github/skills/spine-review and .opencode/skills/spine-review in your project.

What does Spine Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Spine Review is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Glob, Grep, WebFetch, WebSearch, Task, TodoWrite, AskUserQuestion.

Does Spine Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Spine Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Spine Review use?

Spine Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spine Review use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Spine Review?

Skills that share tags, products or a category with Spine Review: Resilience (codewithmukesh/dotnet-claude-kit, 756 stars), Azure Open Datasets (MicrosoftDocs/Agent-Skills, 776 stars), Evaluate PR Tests (dotnet/maui, 23k stars) and Code Review (polyipseity/obsidian-terminal, 951 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spine Review?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.