Agent skill

Corgispec QA Backend

by ricoyudog in ricoyudog/Coding_Corgi_flow

Backend logic walkthrough — traces call chain from real entry points, verifies data integrity across layers

MITAuto-check passedTesting & QA

Install Corgispec QA Backend

skills CLI
$ npx skills add ricoyudog/Coding_Corgi_flow --skill corgispec-qa-backend -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ricoyudog/Coding_Corgi_flow corgispec-qa-backend --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ricoyudog/Coding_Corgi_flow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/atoms/corgispec-qa-backend .claude/skills/corgispec-qa-backend && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
corgispec-qa-backend
GitHub stars
104
Token cost
~1.6k tokens
SKILL.md length
615 words
Files
2
Skills in repo
18
Repo updated
First seen
Licence
MIT

At a glance

Backend logic walkthrough — traces call chain from real entry points, verifies data integrity across layers

  • Works in 6 steps: Identify the entry point → Trace the call chain (3-layer depth) → Verify the happy path → …
  • Testing & QA work in your project
  • SKILL.md covers Overview, When to Use, Preconditions and Walkthrough Procedure, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Corgispec QA Backend is an agent skill from ricoyudog/Coding_Corgi_flow. Backend logic walkthrough — traces call chain from real entry points, verifies data integrity across layers

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `skill.meta.json`). Compatibility notes: Requires a backend codebase with identifiable entry points (routes, handlers, commands).

It sits in Testing & QA. The repository describes itself as: OpenSpec GitFlow — structured AI engineering workflows with issue tracking. The licence is MIT.

When your agent uses it

  • Testing & QA work in your project

Example prompts

  • “/corgispec-qa-backend”

Requirements

  • Compatibility (from SKILL.md): Requires a backend codebase with identifiable entry points (routes, handlers, commands).

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Identify the entry point
  2. Trace the call chain (3-layer depth)
  3. Verify the happy path
  4. Verify one error path
  5. Auth pyramid verification
  6. DB write/read verification

What it can do on your machine

Read from SKILL.md and the folder at commit 461555c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires a backend codebase with identifiable entry points (routes, handlers, commands).

    From compatibility in the SKILL.md frontmatter.

Context cost

Corgispec QA Backend loads about 1.6k tokens when it runs. Until then it costs about 32 tokens; SKILL.md has 615 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ricoyudog/Coding_Corgi_flow at commit 461555c, republished under its MIT licence (© ricoyudog). 615 words, ~1,621 tokens.

Download SKILL.mdSave it as .claude/skills/corgispec-qa-backend/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
corgispec-qa-backend
description
Backend logic walkthrough — traces call chain from real entry points, verifies data integrity across layers
compatibility
Requires a backend codebase with identifiable entry points (routes, handlers, commands).
license
MIT
metadata.author
corgispec
metadata.version
1.0.0
metadata.generatedBy
1.0.0

Backend logic walkthrough for QA verification.

Overview

This skill guides a structured walkthrough of backend logic by tracing the call chain from a real entry point (route handler, CLI command, event listener) down through service, repository, and data layers. It verifies data integrity, auth enforcement, and error handling at each layer.

When to Use

  • Verifying a new or modified backend feature works correctly end-to-end
  • QA review of a pull request's backend changes
  • Investigating whether auth, validation, and error paths are complete
  • Confirming DB read/write operations match expected behavior

Do not use this skill for frontend-only changes, infrastructure/CI changes, or pure refactors with no behavioral change.

Preconditions

  • Target feature or endpoint is identified
  • Codebase is accessible and readable
  • qa-testcases.md exists in the change directory (if reporting results)

Walkthrough Procedure

1. Identify the entry point

Find the root function for the feature under test:

  • Route handler (e.g., POST /api/users)
  • Event listener (e.g., onOrderCreated)
  • CLI command handler
  • Scheduled job entry

Record: file path, function name, HTTP method + path (if applicable).

2. Trace the call chain (3-layer depth)

Walk through exactly 3 layers from the entry point:

LayerTypical RoleWhat to Record
L1 — Controller/HandlerRequest parsing, input validation, auth checkInput shape, auth requirement, early returns
L2 — Service/Use-caseBusiness logic, orchestrationTransformations, conditional branches, side effects
L3 — Repository/DataDB queries, external API callsQuery shape, write operations, return shape

At each layer record:

  • Function signature (params + return type)
  • Input values that reach this layer (trace from caller)
  • Return values passed back to caller
  • Side effects (DB writes, events emitted, external calls)
3. Verify the happy path

Trace one successful request end-to-end:

  1. Construct a valid input at L1
  2. Follow the data through L2 transformations
  3. Confirm L3 performs the expected DB write/read
  4. Verify the response returned to the caller matches expected shape

Record: input → each layer's transformation → final output.

4. Verify one error path

Choose the most critical error scenario:

  • Invalid input (400)
  • Unauthorized access (401/403)
  • Resource not found (404)
  • Business rule violation (409/422)

Trace the error from point of detection back to the response:

  1. Where is the error detected? (which layer, which condition)
  2. How does it propagate? (thrown exception, error return, early return)
  3. What response does the caller receive? (status code, error body)
Show full SKILL.md (239 more words)Show less
5. Auth pyramid verification

Check auth enforcement at each level of the pyramid:

LevelCheckPass Criteria
UnauthenticatedNo token/sessionReturns 401
AuthenticatedValid token, wrong roleReturns 403 (if role-gated)
AuthorizedValid token, correct role, wrong resourceReturns 403 or 404
AdminAdmin tokenFull access confirmed

For each level, confirm the check happens BEFORE any business logic or DB access.

6. DB write/read verification

For every DB operation found in L3:

  • Writes: Confirm the written shape matches the schema. Confirm no partial writes on error (transaction or rollback).
  • Reads: Confirm query filters are correct (no over-fetching, no missing tenant/owner scoping).
  • Ordering: If the operation is read-after-write in the same flow, confirm consistency.

Reading qa-testcases.md

If qa-testcases.md exists in the change directory, read it before starting the walkthrough. It contains pre-defined test scenarios that MUST be covered:

## Format of qa-testcases.md

### <Feature Name>

| ID | Scenario | Input | Expected | Priority |
|----|----------|-------|----------|----------|
| TC-001 | ... | ... | ... | P0 |

Map each test case to a walkthrough path. After completing the walkthrough, report coverage:

  • Which test cases were verified via trace
  • Which test cases could NOT be verified (and why)

Reporting Format

After completing the walkthrough, produce a summary in this structure:

markdown
## QA Backend Walkthrough: <Feature Name>

### Entry Point
- **Path**: `<file>:<line>`
- **Function**: `<name>`
- **Route**: `<METHOD /path>` (if applicable)

### Call Chain
| Layer | File | Function | Input | Output | Side Effects |
|-------|------|----------|-------|--------|--------------|
| L1 | ... | ... | ... | ... | ... |
| L2 | ... | ... | ... | ... | ... |
| L3 | ... | ... | ... | ... | ... |

### Happy Path
- Input: ...
- Flow: L1 → L2 → L3
- DB Operation: ...
- Response: ...
- **Status: PASS / FAIL**

### Error Path (<which error>)
- Trigger: ...
- Detection point: L<n>, condition: ...
- Propagation: ...
- Response: status=<code>, body=...
- **Status: PASS / FAIL**

### Auth Pyramid
| Level | Tested | Result |
|-------|--------|--------|
| Unauthenticated | Yes/No | PASS/FAIL |
| Authenticated | Yes/No | PASS/FAIL |
| Authorized | Yes/No | PASS/FAIL |
| Admin | Yes/No | PASS/FAIL |

### DB Integrity
| Operation | Table | Verified | Notes |
|-----------|-------|----------|-------|
| INSERT | ... | Yes/No | ... |
| SELECT | ... | Yes/No | ... |

### Test Case Coverage (from qa-testcases.md)
| ID | Covered | Method | Notes |
|----|---------|--------|-------|
| TC-001 | Yes/No | Trace/Manual | ... |

### Verdict
- [ ] Happy path verified
- [ ] Error path verified
- [ ] Auth pyramid complete
- [ ] DB integrity confirmed
- **Overall: PASS / FAIL / PARTIAL**

Tips

  • If the codebase uses middleware for auth, trace through the middleware FIRST before entering the handler.
  • For microservices, treat inter-service calls as an L3 boundary (record request/response shape).
  • If you cannot reach 3 layers (e.g., thin handler directly calling DB), note the collapsed layers and verify what exists.
  • Prefer reading actual code over documentation — docs may be stale.

© ricoyudog, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .claude/skills/atoms/corgispec-qa-backend of ricoyudog/Coding_Corgi_flow.

  • SKILL.md
  • skill.meta.json

Open the folder on GitHubat commit 461555c

Compare with similar skills

Corgispec QA Backend next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Corgispec QA Backend compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Corgispec QA Backend this skillricoyudog/Coding_Corgi_flow104—~1.6kAutomated safety check: PassMIT
Web Application Testinganthropics/skills180k51 repos~966Automated safety check: PassApache-2.0
Diagnosing Bugsfossasia/eventyay-interpretation1.6k32 repos~2.1kAutomated safety check: PassApache-2.0
TDDpietheinstrengholt/rssmonster56430 repos~906Automated safety check: PassMIT
TDD WorkflowhellangleZ/burn-in-cceverywhere-ralph11211 repos~2.4kAutomated safety check: PassNone
TDDsanity-io/sanity6.4k20 repos~1kAutomated safety check: PassMIT

Similar skills

  • Web Application Testing

    anthropics/skills

    Official

    Tests local web applications with Python Playwright scripts, checking frontend behavior, capturing screenshots and reading browser console logs.

    180k GitHub starsUsed in 51 repos~966 tokens
    Testing & QAAuto-check passed
  • Diagnosing Bugs

    fossasia/eventyay-interpretation

    Diagnosis loop for hard bugs and performance regressions. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 32 repos~2.1k tokens
    Testing & QAAuto-check passed
  • TDD

    pietheinstrengholt/rssmonster

    Test-driven development. An agent skill from pietheinstrengholt/rssmonster.

    564 GitHub starsUsed in 30 repos~906 tokens
    Testing & QAAuto-check passed
  • TDD Workflow

    hellangleZ/burn-in-cceverywhere-ralph

    A skill your agent uses when writing new features, fixing bugs, or refactoring code.

    112 GitHub starsUsed in 11 repos~2.4k tokens
    Testing & QAAuto-check passed
  • TDD

    sanity-io/sanity

    Official

    Test-driven development with red-green-refactor loop. An agent skill from sanity-io/sanity.

    6.4k GitHub starsUsed in 20 repos~1k tokens
    Testing & QAAuto-check passed
  • Context Driven Development

    Ibrahim-3d/orchestrator-supaconductor

    A skill your agent uses when working with Conductor's context-driven development methodology, managing project context artifacts, or understanding the relationship between product.md, tech-stack.md…

    381 GitHub starsUsed in 9 repos~2.9k tokens
    Testing & QAAuto-check passed

More from ricoyudog/Coding_Corgi_flow

All 18 skills in this repo
  • Corgispec Propose

    ricoyudog/Coding_Corgi_flow

    Create or complete one RFC-first CorgiSpec planning package from an accepted unbound RFC Slice or a closed maintenance exemption.

    104 GitHub stars~1.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Corgispec Update

    ricoyudog/Coding_Corgi_flow

    Reconcile an existing CorgiSpec planning package after intent, requirements, scenarios, design, or task sequencing changes.

    104 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Corgispec Ask

    ricoyudog/Coding_Corgi_flow

    Answer pending Obsidian questions from CorgiSpec Memory/Wiki with early-stop retrieval, source citations, and a strict file budget.

    104 GitHub stars~689 tokensUpdated 1 mo ago
    Auto-check passed
  • Corgispec Install

    ricoyudog/Coding_Corgi_flow

    A skill your agent uses when installing, updating, or verifying this repo's project-local Corgi GitFlow assets in a target project.

    104 GitHub stars~4.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Corgispec Lint

    ricoyudog/Coding_Corgi_flow

    Validate CorgiSpec v4 Memory/Wiki structure, freshness, source integrity, delivery extraction, bridge drift, and legacy preservation.

    104 GitHub stars~987 tokensUpdated 1 mo ago
    Auto-check passed
  • Corgispec Rfc

    ricoyudog/Coding_Corgi_flow

    Guide a human-authored CorgiSpec RFC through isolated draft creation, validation, explicit interactive approval, merge effectiveness, collision renumbering, and amendments.

    104 GitHub stars~777 tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Corgispec QA Backend

What does Corgispec QA Backend do?

Backend logic walkthrough — traces call chain from real entry points, verifies data integrity across layers. Corgispec QA Backend is an agent skill from ricoyudog/Coding_Corgi_flow.

When should I use Corgispec QA Backend?

Corgispec QA Backend fits situations like: testing & QA work in your project.

How do I install Corgispec QA Backend in Claude Code?

Run `npx skills add ricoyudog/Coding_Corgi_flow --skill corgispec-qa-backend -a claude-code`. Or copy the skill folder (.claude/skills/atoms/corgispec-qa-backend in ricoyudog/Coding_Corgi_flow) into .claude/skills/corgispec-qa-backend in your project. Claude Code loads it when a task matches its description.

How do I install Corgispec QA Backend in Codex?

Run `npx skills add ricoyudog/Coding_Corgi_flow --skill corgispec-qa-backend -a codex`. Or copy the skill folder (.claude/skills/atoms/corgispec-qa-backend in ricoyudog/Coding_Corgi_flow) into .agents/skills/corgispec-qa-backend in your project. Codex loads it when a task matches its description.

Can I use Corgispec QA Backend in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ricoyudog/Coding_Corgi_flow --skill corgispec-qa-backend -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/corgispec-qa-backend, .gemini/skills/corgispec-qa-backend, .github/skills/corgispec-qa-backend and .opencode/skills/corgispec-qa-backend in your project.

What does Corgispec QA Backend need to run?

SKILL.md names no scripts, command-line tools or credentials: Corgispec QA Backend is instructions for the agent only. Compatibility (from SKILL.md): Requires a backend codebase with identifiable entry points (routes, handlers, commands)..

Does Corgispec QA Backend access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Corgispec QA Backend safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Corgispec QA Backend use?

Corgispec QA Backend is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Corgispec QA Backend use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Corgispec QA Backend?

Skills that share tags, products or a category with Corgispec QA Backend: Web Application Testing (anthropics/skills, 180k stars), Diagnosing Bugs (fossasia/eventyay-interpretation, 1.6k stars), TDD (pietheinstrengholt/rssmonster, 564 stars) and TDD Workflow (hellangleZ/burn-in-cceverywhere-ralph, 112 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Corgispec QA Backend?

ricoyudog (a GitHub user) maintains it in ricoyudog/Coding_Corgi_flow, which has 104 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on August 19, 2026.

Source: ricoyudog/Coding_Corgi_flow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.