Agent skill

Backoffice

by latitude-dev in latitude-dev/latitude-llm

Adding, modifying, or guarding staff-only /backoffice features — cross-organisation admin tools gated behind users.role === "admin".

MITAuto-check passed

Install Backoffice

skills CLI
$ npx skills add latitude-dev/latitude-llm --skill backoffice -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install latitude-dev/latitude-llm backoffice --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/latitude-dev/latitude-llm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/backoffice .claude/skills/backoffice && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
backoffice
GitHub stars
4.7k
Token cost
~1.9k tokens
SKILL.md length
732 words
Files
1
Skills in repo
28
Repo updated
First seen
Licence
MIT

At a glance

Adding, modifying, or guarding staff-only /backoffice features — cross-organisation admin tools gated behind users.role === "admin".

  • Works in 3 steps: Route loader guard (UI layer) → Server-function guard (RPC layer) → Database access guard
  • SKILL.md covers Absolute security invariant, The three guards, Package layout and Adapter discipline, plus 3 more sections
  • Calls pnpm

What it does

Backoffice is an agent skill from latitude-dev/latitude-llm. Adding, modifying, or guarding staff-only /backoffice features — cross-organisation admin tools gated behind users.role === "admin".

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Open-source observability for AI agents. Find where your agents fail, dispatch your coding agent to fix it, and verify the fix against real traces. The licence is MIT.

Example prompts

  • “/backoffice”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Route loader guard (UI layer)
  2. Server-function guard (RPC layer)
  3. Database access guard

What it can do on your machine

Read from SKILL.md and the folder at commit 87e8aa0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Backoffice loads about 1.9k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 732 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from latitude-dev/latitude-llm at commit 87e8aa0, republished under its MIT licence (© latitude-dev). 732 words, ~1,891 tokens.

Download SKILL.mdSave it as .claude/skills/backoffice/SKILL.md (or your agent's skills folder).
name
backoffice
description
Adding, modifying, or guarding staff-only `/backoffice` features — cross-organisation admin tools gated behind `users.role === "admin"`.

Backoffice (staff-only admin area)

When to use: Adding, modifying, or guarding staff-only /backoffice features — cross-organisation admin tools gated behind users.role === "admin". The backoffice is where platform staff reproduce customer-reported bugs, spot-check data across tenants, and (future) impersonate users for support.

Absolute security invariant

Non-admin users — authenticated or not — MUST NOT be able to access, enumerate, or fingerprint the backoffice surface. Every response is indistinguishable from hitting a random 404. This is enforced by three independent guards; every guard is ship-blocking on its own.

The three guards

1. Route loader guard (UI layer)

apps/web/src/routes/backoffice/route.tsx asserts user.role === "admin" in beforeLoad and loader, throwing notFound() (not redirect or 403 — those leak the path) on failure. TanStack Start code-splitting means non-admins never fetch the backoffice chunk.

2. Server-function guard (RPC layer)

Every backoffice createServerFn handler MUST attach adminMiddleware from apps/web/src/server/admin-middleware.ts. The middleware fetches the session with Better Auth's cookie cache bypassed (so DB-level role demotions take effect on the next request, not 5 minutes later), rejects non-admins with NotFoundError (not 401/403 — the error shape must not fingerprint the admin surface), and injects context.adminUserId + context.user so handlers have admin identity available without re-fetching.

ts
export const adminThing = createServerFn({ method: "GET" })
  .middleware([adminMiddleware])                    // GUARD, before input validation
  .inputValidator(inputSchema)
  .handler(async ({ data, context }): Promise<ThingDto> => {
    const client = getAdminPostgresClient()
    const result = await Effect.runPromise(
      thingUseCase(data).pipe(
        withPostgres(ThingRepositoryLive, client),  // org defaults to "system" → RLS off
        withTracing,
      ),
    )
    return toDto(result)
  })

Middleware runs before inputValidator, so abusive payloads get rejected one step earlier (no Zod parse overhead on non-admin probes).

The sole exception is stopImpersonating, which uses impersonatingMiddleware (from the same file) instead. During an active impersonation the current session's user.role is the target's role (usually "user"), so an admin-role check would reject the very call the admin needs to exit impersonation. impersonatingMiddleware gates on session.impersonatedBy being set and injects both context.adminUserId (recovered before Better Auth swaps the cookie back) and context.targetUserId for the audit event.

Do not wrap createServerFn in a factory (e.g. createBackofficeServerFn = (opts) => createServerFn(opts).middleware([...])). TanStack Start's Vite plugin detects server functions by pattern-matching the literal createServerFn(...).handler(inlineFn) chain at the call site — a factory hides those tokens behind a different name, the compiler skips the file, and Node-only module-level imports (withTracing, getAdminPostgresClient, …) leak into the browser bundle, breaking pnpm build with MISSING_EXPORT errors against @repo/observability/browser.ts. Keep createServerFn literal at every call site and attach the middleware there; the .middleware(…) method is part of the chain the compiler recognises. Attaching at each call site also keeps the "which guard does this endpoint use?" decision visible in the handler body — important because stopImpersonating uses a different middleware than the rest.

The route loader in routes/backoffice/route.tsx cannot use createServerFn middleware (route loaders aren't server functions). It calls requireAdminSession() from admin-auth.ts instead — same underlying fresh-session + role check, just exposed as a plain async helper. Both helpers share assertAdminUser and getFreshSession.

Show full SKILL.md (307 more words)Show less
3. Database access guard

Admin queries run through getAdminPostgresClient() (apps/web/src/server/clients.ts), a pool on the separate LAT_ADMIN_DATABASE_URL superuser secret. withPostgres defaults the organisation scope to OrganizationId("system"), which is the only sanctioned signal to skip the RLS set_config('app.current_organization_id', …) call (see packages/platform/db-postgres/src/sql-client.ts). Admin handlers have no organisation context — passing one into withPostgres from a backoffice handler is a bug.

Package layout

@domain/admin
  src/
    <feature>/                   # one folder per feature (search, users, ...)
      *-result.ts | entity.ts    # Zod schemas + types
      *-repository.ts            # port (class … extends ServiceMap.Service<…>)
      *.ts                       # use-case(s)
      *.test.ts                  # pure use-case tests with fake ports
      index.ts                   # feature barrel
    index.ts                     # re-exports every feature

Keep @domain/admin as one package with feature folders — do not split into @domain/admin-search, @domain/admin-users, etc. Features share enough scaffolding (policy, audit, RLS-bypass) that splitting causes churn without benefit.

Web-app per-feature split mirrors the package:

apps/web/src/domains/admin/
  <feature>.functions.ts         # createServerFn handler(s) + DTOs (guard = first line)
  <feature>.functions.test.ts    # input-schema tests

Routes live at apps/web/src/routes/backoffice/<feature>/ (using route.tsx / index.tsx, not _layout.tsx — the _ prefix contributes no URL segment and would collide with _authenticated/index.tsx on /).

Adapter discipline

Admin repository adapters (e.g. AdminSearchRepositoryLive in @platform/db-postgres) run queries without an organization_id filter. This is only safe because the admin client + "system" scope bypasses RLS. Every admin adapter source file carries a header warning explaining the wiring contract — copy that pattern when adding new adapters.

Error discipline

  • NotFoundError, not UnauthorizedError, for every admin guard failure.
  • No 401/403/redirect responses anywhere — all refusals look identical to a 404.
  • Don't log messages that mention "admin" or "role" at the error path — error shapes/messages fingerprint the surface.

Roles

  • users.role is the global platform-staff flag ("user" | "admin"). DBA-only (Better Auth additionalFields.role declares input: false).
  • members.role is per-organisation ("owner" | "admin" | "member"). Different concept. A user who is members.role = "admin" of their own org has zero backoffice access.

Tests

  • Use-case tests (@domain/admin): pure functions + fake ports via Layer.succeed(Port, stubImpl). No DB.
  • Adapter tests (@platform/db-postgres): PGlite via setupTestPostgres(); drive through withPostgres(Live, pg.adminPostgresClient) to match production admin wiring.
  • Guard tests (apps/web/src/server/admin-auth.test.ts): cover admin / user / null / undefined / missing-role, and assert the error shape does not fingerprint the admin surface.
  • Server-function tests: exercise the exported input schema, not the RPC runtime. The guard is already covered by admin-auth.test.ts — don't reassert it per handler.

© latitude-dev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/backoffice of latitude-dev/latitude-llm.

Open the folder on GitHubat commit 87e8aa0

Compare with similar skills

Backoffice next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Backoffice compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Backoffice this skilllatitude-dev/latitude-llm4.7k—~1.9kAutomated safety check: PassMIT
Safety Guardaffaan-m/ECC274k2 repos~554Automated safety check: NotesMIT
Guard Modegarrytan/gstack136k—~919Automated safety check: NotesMIT
Safety Guardaffaan-m/ECC274k—~323Automated safety check: NotesMIT
Safety Guardaffaan-m/ECC274k—~255Automated safety check: NotesMIT
Docs Guardsickn33/agentic-awesome-skills47k1 repos~2kAutomated safety check: PassMIT

Similar skills

  • Safety Guard

    affaan-m/ECC

    Guard against destructive operations with three modes: Careful intercepts dangerous commands (rm -rf, git push --force, DROP TABLE) for confirmation, Freeze locks writes to one directory, and Guard…

    274k GitHub starsUsed in 2 repos~554 tokens
    DevelopmentAuto-check: notes
  • Guard Mode

    garrytan/gstack

    Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems.

    136k GitHub stars~919 tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Safety Guard

    affaan-m/ECC

    本番システムでの作業時や、エージェントを自律的に実行する際に破壊的な操作を防ぐためにこのスキルを使用してください. An agent skill from affaan-m/ECC.

    274k GitHub stars~323 tokensUpdated 2 days ago
    Auto-check: notes
  • Safety Guard

    affaan-m/ECC

    使用此技能可防止在生产系统上工作或自主运行代理时进行破坏性操作。

    274k GitHub stars~255 tokensUpdated 2 days ago
    Auto-check: notes
  • Docs Guard

    sickn33/agentic-awesome-skills

    Review generated or changed documentation before it ships, including READMEs, API references, docstrings, changelogs, tutorials, and documentation sites.

    47k GitHub starsUsed in 1 repo~2k tokens
    DevelopmentAuto-check passed
  • Woo Guard

    sickn33/agentic-awesome-skills

    Review generated or changed WooCommerce extensions, payment and shipping integrations, checkout customizations, and order or product logic.

    47k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed

More from latitude-dev/latitude-llm

All 28 skills in this repo
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Auto-check passed
  • Artifact Designer

    latitude-dev/latitude-llm

    Create, validate, preview, and publish self-contained HTML artifacts.

    4.7k GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • CI Watchdog

    latitude-dev/latitude-llm

    Continuously monitor GitHub PR CI checks and automatically fix failures until all checks pass.

    4.7k GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Temporal Developer

    latitude-dev/latitude-llm

    This skill should be used when the user asks to "create a Temporal workflow", "write a Temporal activity", "debug stuck workflow", "fix non-determinism error", "Temporal Python", "Temporal…

    4.7k GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Docs

    latitude-dev/latitude-llm

    Review the current conversation context and git changes, then persist durable repository knowledge into dev-docs/.md by domain and into AGENTS.md for cross-cutting repo rules.

    4.7k GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Managing Maintenance Windows

    latitude-dev/latitude-llm

    Enables or disables Latitude production maintenance mode by redirecting all publicly exposed production services to the Better Stack status page.

    4.7k GitHub stars~802 tokensUpdated yesterday
    Auto-check passed

Questions about Backoffice

What does Backoffice do?

Adding, modifying, or guarding staff-only /backoffice features — cross-organisation admin tools gated behind users.role === "admin". Backoffice is an agent skill from latitude-dev/latitude-llm.role === "admin".

How do I install Backoffice in Claude Code?

Run `npx skills add latitude-dev/latitude-llm --skill backoffice -a claude-code`. Or copy the skill folder (.agents/skills/backoffice in latitude-dev/latitude-llm) into .claude/skills/backoffice in your project. Claude Code loads it when a task matches its description.

How do I install Backoffice in Codex?

Run `npx skills add latitude-dev/latitude-llm --skill backoffice -a codex`. Or copy the skill folder (.agents/skills/backoffice in latitude-dev/latitude-llm) into .agents/skills/backoffice in your project. Codex loads it when a task matches its description.

Can I use Backoffice in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add latitude-dev/latitude-llm --skill backoffice -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/backoffice, .gemini/skills/backoffice, .github/skills/backoffice and .opencode/skills/backoffice in your project.

What does Backoffice need to run?

Going by SKILL.md and its folder, Backoffice needs the command-line tools its instructions call (pnpm).

Does Backoffice access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Backoffice safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Backoffice use?

Backoffice is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Backoffice use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Backoffice?

Skills that share tags, products or a category with Backoffice: Safety Guard (affaan-m/ECC, 274k stars), Guard Mode (garrytan/gstack, 136k stars), Safety Guard (affaan-m/ECC, 274k stars) and Safety Guard (affaan-m/ECC, 274k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Backoffice?

latitude-dev (a GitHub organization) maintains it in latitude-dev/latitude-llm, which has 4,712 GitHub stars. The repository holds 28 skills in this directory. The repository was last updated on October 6, 2026.

Source: latitude-dev/latitude-llm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.