Agent skill

Cm Backend Engineer

by kingxiaozhe in kingxiaozhe/cm-workflow

后端 API 工程师 Skill,执行服务端 API 层开发(路由、业务逻辑、鉴权中间件、缓存、队列),自动适配语言和框架

MITAuto-check passedBackend & APIs

Install Cm Backend Engineer

skills CLI
$ npx skills add kingxiaozhe/cm-workflow --skill cm-backend-engineer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kingxiaozhe/cm-workflow cm-backend-engineer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kingxiaozhe/cm-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cm-backend-engineer .claude/skills/cm-backend-engineer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cm-backend-engineer
GitHub stars
104
Token cost
~552 tokens
SKILL.md length
156 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

后端 API 工程师 Skill,执行服务端 API 层开发(路由、业务逻辑、鉴权中间件、缓存、队列),自动适配语言和框架

  • Works in 6 steps: 识别技术栈 → 读取上下文 → 契约纪律(本 skill 核心) → …
  • Backend & APIs work in your project
  • SKILL.md covers 职责边界, 触发条件, 工作流程 and 常见坑, plus 1 more section
  • Calls npm

What it does

Cm Backend Engineer is an agent skill from kingxiaozhe/cm-workflow. 后端 API 工程师 Skill,执行服务端 API 层开发(路由、业务逻辑、鉴权中间件、缓存、队列),自动适配语言和框架

Its SKILL.md is about 550 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. The repository describes itself as: Codex-native, spec-driven AI Agent workflow with Claude Code compatibility, independent review, QA, fixes, and refactors. The licence is MIT.

When your agent uses it

  • Backend & APIs work in your project

Example prompts

  • “/cm-backend-engineer”

Requirements

  • Python 3
  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. 识别技术栈
  2. 读取上下文
  3. 契约纪律(本 skill 核心)
  4. 开发
  5. 安全检查
  6. 验证

What it can do on your machine

Read from SKILL.md and the folder at commit 82d43f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cm Backend Engineer loads about 552 tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 156 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~552

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kingxiaozhe/cm-workflow at commit 82d43f0, republished under its MIT licence (© kingxiaozhe). 156 words, ~552 tokens.

Download SKILL.mdSave it as .claude/skills/cm-backend-engineer/SKILL.md (or your agent's skills folder).
name
cm-backend-engineer
description
后端 API 工程师 Skill,执行服务端 API 层开发(路由、业务逻辑、鉴权中间件、缓存、队列),自动适配语言和框架

cm-backend-engineer — 后端 API 工程师

执行服务端 API 层开发任务。自动识别语言和框架。

职责边界

  • 管:路由/控制器、业务逻辑、鉴权与权限中间件、缓存策略、消息队列、对外接口说明
  • 不管:数据库 schema 与 migration(→ cm-database-engineer)、测试补全与 E2E(→ cm-qa-engineer)

触发条件

由 /cm-ai 自动调用,当 task 涉及后端 API 开发时触发。

工作流程

1. 识别技术栈

自动检测,不做硬编码假设:

  • 语言/运行时:Node.js / Python / Go / Java / Rust
  • 框架:Express / Fastify / Hono / NestJS / FastAPI / Django / Gin / Spring 等
  • 鉴权方案:JWT / Session / OAuth2 / BetterAuth 等(读现有中间件与依赖判断)
  • 接口风格:REST / GraphQL / tRPC / gRPC(读路由与已有接口定义判断)
2. 读取上下文
  • .claude/rules/backend-api.md、.claude/rules/security.md(如存在)
  • design.md 中的接口契约——本 skill 的最高约束
  • 现有路由组织、错误处理约定、中间件链
3. 契约纪律(本 skill 核心)

design.md 的接口契约是前后端并行的生命线,执行三级协议:

  1. 执行者只报不改:实现中发现契约不合理或不完整 → 不得静默偏离、不得直接修改 design.md,将偏差和理由写入完成汇报的「契约相关」栏
  2. 主流程小改留痕:字段增补等小偏差由主流程更新 design.md 并标注版本(对齐 [CHANGED] 惯例)
  3. 大改必须问人:偏差影响已完成任务所依赖的契约(会引发返工)→ 强制暂停人工确认

实现完成后逐条核对:路径、方法、请求/响应字段、错误码与契约一致。

4. 开发

接口实现:

  • 遵循项目已有的路由组织和分层(controller/service/repository 等按项目实际)
  • 错误处理统一:错误码、错误体结构跟随项目约定,无约定则建立一处并全局复用
  • 输入验证在边界层完成,校验库跟随项目已有选择
  • 幂等性:写操作考虑重复提交(幂等键/去重),支付类接口强制

鉴权与权限:

  • 复用项目已有的鉴权中间件,不另起炉灶
  • 权限检查靠近资源(handler 层),不散落各处
  • 敏感操作留审计日志

性能与可靠性(以下为默认值,.claude/rules/ 有规定时以 rules 为准):

  • 外部调用必须有超时,默认 5s
  • 列表接口必须分页,默认页大小 20
  • 高频读考虑缓存、写路径考虑队列削峰——是否引入新基础设施以 design.md 为准,不擅自添加
5. 安全检查
  • 密钥/连接串一律环境变量,绝不硬编码
  • 注入防护:参数化查询、模板转义(与 database skill 双保险)
  • 鉴权绕过自查:逐条核对本次新增路由是否漏挂鉴权中间件
  • 日志不输出密码、token、证件号等敏感字段
6. 验证
bash
# 根据项目实际命令执行
npm run lint && npm run typecheck
npm run build

启动服务,对本 task 涉及的接口逐个实测(curl/httpie):正常流 + 至少一个异常流(4xx)。

常见坑

问题处理
新路由漏挂鉴权中间件按路由分组统一挂载,逐条核对本次新增路由
外部调用无超时导致雪崩统一封装 HTTP client,强制超时与重试上限
错误体结构不一致,前端难处理全局错误处理器统一出口,禁止 handler 内裸造错误体
时间/时区序列化不一致统一 UTC + ISO 8601 出参,入参解析集中处理
阻塞事件循环(大 JSON / 同步加密)大计算移 worker 或队列,序列化分页
分页游标与排序不稳定排序键唯一化(时间戳+id),游标编码含排序上下文

输出

  • 创建/修改的文件列表
  • 验证结果(lint / build / 接口实测)
  • 契约实现情况:逐条列出实现的接口,标注与 design.md 的偏差(无偏差则写"完全一致")
  • 需要其他工种配合的事项(如前端可替换 mock 的接口清单、需要数据库配合的字段)

© kingxiaozhe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cm-backend-engineer of kingxiaozhe/cm-workflow.

Open the folder on GitHubat commit 82d43f0

Compare with similar skills

Cm Backend Engineer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cm Backend Engineer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cm Backend Engineer this skillkingxiaozhe/cm-workflow104—~552Automated safety check: PassMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api43k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    43k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from kingxiaozhe/cm-workflow

All 23 skills in this repo
  • Cm Fix

    kingxiaozhe/cm-workflow

    用户说“修复这个可复现 bug”或要求根据失败报告修代码时使用。执行红灯测试、根因定位、最小修复、独立审查和回归;尚未确认的问题先用 cm-test,新功能和架构重设计转交 cm-prd。

    104 GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Cm Idea

    kingxiaozhe/cm-workflow

    用户说“我有个点子”“帮我梳理产品”或需要先聊清目标时使用。通过逐题访谈整理为可交给 cm-prd 的 PRD;已有明确需求文档时改用 cm-prd,不写代码、不拆开发任务。

    104 GitHub starsUsed in 1 repo~419 tokens
    Auto-check passed
  • Cm Refactor

    kingxiaozhe/cm-workflow

    用户明确要求“只整理结构,不改变行为”时使用。执行边界分流、行为判官、分批重构和独立审查;缺陷修复转交 cm-fix,新增或变化的业务行为转交 cm-prd。

    104 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Cm Security

    kingxiaozhe/cm-workflow

    用户运行 cm-security,或要求代码安全扫描、漏洞检查、密钥泄露排查、依赖漏洞检查时使用。默认检查当前分支相对主分支及已跟踪未提交修改,结合业务地图复核;--all 检查全部已跟踪文件。只报告问题,不自动修复、安装、升级或发布。安装自检用 cm-check,功能测试与覆盖率用 cm-test。

    104 GitHub starsUsed in 1 repo~744 tokens
    Auto-check passed
  • Cm AI

    kingxiaozhe/cm-workflow

    用户明确说“规格已确认,开始实现”或要求按已审批 CM specs 开发时使用。新任务默认由 JS workflow 驱动 N1-N8,完成开发、独立审查、QA 与文档同步;模糊点子、未审规格和单独一句“继续”不能触发编码批准。

    104 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Cm Check

    kingxiaozhe/cm-workflow

    用户说“检查工作流是否安装正确”“为什么找不到 cm 命令”时使用。默认查询 npm 稳定版,有新版自动升级已管理的 CM 安装,再检查插件、核心 Skills、兼容包装与模板引用;不测试或修改业务代码。

    104 GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Cm Backend Engineer

What does Cm Backend Engineer do?

后端 API 工程师 Skill,执行服务端 API 层开发(路由、业务逻辑、鉴权中间件、缓存、队列),自动适配语言和框架. Cm Backend Engineer is an agent skill from kingxiaozhe/cm-workflow.

When should I use Cm Backend Engineer?

Cm Backend Engineer fits situations like: backend & APIs work in your project.

How do I install Cm Backend Engineer in Claude Code?

Run `npx skills add kingxiaozhe/cm-workflow --skill cm-backend-engineer -a claude-code`. Or copy the skill folder (skills/cm-backend-engineer in kingxiaozhe/cm-workflow) into .claude/skills/cm-backend-engineer in your project. Claude Code loads it when a task matches its description.

How do I install Cm Backend Engineer in Codex?

Run `npx skills add kingxiaozhe/cm-workflow --skill cm-backend-engineer -a codex`. Or copy the skill folder (skills/cm-backend-engineer in kingxiaozhe/cm-workflow) into .agents/skills/cm-backend-engineer in your project. Codex loads it when a task matches its description.

Can I use Cm Backend Engineer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kingxiaozhe/cm-workflow --skill cm-backend-engineer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cm-backend-engineer, .gemini/skills/cm-backend-engineer, .github/skills/cm-backend-engineer and .opencode/skills/cm-backend-engineer in your project.

What does Cm Backend Engineer need to run?

Going by SKILL.md and its folder, Cm Backend Engineer needs the command-line tools its instructions call (npm). Our summary lists: Python 3; Node.js.

Does Cm Backend Engineer access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cm Backend Engineer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cm Backend Engineer use?

Cm Backend Engineer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cm Backend Engineer use?

About 552 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cm Backend Engineer?

Skills that share tags, products or a category with Cm Backend Engineer: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 43k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cm Backend Engineer?

kingxiaozhe (a GitHub user) maintains it in kingxiaozhe/cm-workflow, which has 104 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 8, 2026.

Source: kingxiaozhe/cm-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.