backend-dev-guidelines
Build Reliable TypeScript Backends
Backend teams often produce inconsistent Express services with weak separation, validation, and error handling. This skill supplies reusable architecture, configuration, Prisma, Sentry, Zod, middleware, and testing guidance.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "backend-dev-guidelines" from https://skillstore.io/skills/briandai22-backend-dev-guidelines.md and its manifest at https://skillstore.io/api/skills/briandai22-backend-dev-guidelines/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "backend-dev-guidelines". Plan a user creation endpoint with Prisma and Zod.
Expected outcome:
- Route: validate the request and delegate to the user controller.
- Controller: map the validated request and return a consistent created response.
- Service: enforce uniqueness and business rules through injected dependencies.
- Repository: perform the Prisma create operation and translate database errors.
- Tests: cover success, invalid input, duplicate email, and repository failure.
Using "backend-dev-guidelines". Review an Express route that contains database queries and error formatting.
Expected outcome:
- Move request handling and response formatting into a controller.
- Move business decisions into a service.
- Move repeated Prisma access into a repository.
- Apply shared validation and error middleware at the route boundary.
Using "backend-dev-guidelines". Outline a production readiness review for a notification service.
Expected outcome:
Review middleware order, configuration validation, secret handling, request schemas, retry behavior, Sentry privacy, database transactions, health checks, and integration tests.
Security Audit
High RiskAll 214 static matches are false positives caused by Markdown, imports, template literals, fixed paths, placeholders, and defensive configuration guidance. No malicious intent, prompt injection, reconnaissance, shell execution, or arbitrary file access was found. Two high-impact guidance issues remain: an unsafe session-secret fallback and overly broad Sentry data collection.
Confirmed security concerns (2)
Risk Factors
๐ Env variables (50)
๐ Filesystem access (42)
๐ Network access (4)
โ๏ธ External commands (33)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/briandai22-backend-dev-guidelines/audits/9?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/briandai22-backend-dev-guidelines?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/briandai22-backend-dev-guidelines?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/briandai22-backend-dev-guidelines/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/briandai22-backend-dev-guidelines.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
BrianDai22. (2026). backend-dev-guidelines security audit report (audit version 9) [Author version unspecified]. Skillstore. https://skillstore.io/skills/briandai22-backend-dev-guidelines/audits/9BibTeX citation
@techreport{briandai22-briandai22-backend-dev-guidelines-2026,
author = {BrianDai22},
title = {backend-dev-guidelines security audit report (audit version 9)},
institution = {Skillstore},
year = {2026},
number = {9},
url = {https://skillstore.io/skills/briandai22-backend-dev-guidelines/audits/9},
note = {Author version unspecified}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "backend-dev-guidelines security audit report (audit version 9)"
version: "unspecified"
type: report
authors:
- name: "BrianDai22"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/briandai22-backend-dev-guidelines/audits/9"
identifiers:
- type: other
value: "skillstore:briandai22-backend-dev-guidelines:audit:9"
description: "Skillstore immutable audit report identifier"
Compare variants
5 installable variantsEach author remains a separate installable skill. The recommended variant is ranked by Skillstore evidence.
Why this variant is first
dojocodinglabs-backend-dev-guidelines
2026-09-09
dimon94-backend-dev-guidelines
2026-09-09
diet103-backend-dev-guidelines
2026-09-09
sickn33-backend-dev-guidelines
2026-09-09
briandai22-backend-dev-guidelines
2026-09-09
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Create a Backend Feature
Plan a new endpoint across routing, validation, controller, service, repository, monitoring, and tests.
Standardize a Service Team
Establish shared TypeScript patterns for architecture, configuration, middleware, errors, and database access.
Refactor Legacy Routes
Move business and database logic from large Express routes into testable layers.
Try These Prompts
Plan a TypeScript Express endpoint for [feature]. Identify its route, validation schema, controller, service, repository needs, error handling, and tests.
Review [route file or description] using these backend guidelines. Propose a layered refactor and explain each responsibility change.
Design a TypeScript microservice for [domain]. Define its directories, middleware order, configuration, Prisma access, validation, monitoring, and test strategy.
Audit [feature or service] against the complete guidelines. Prioritize architecture, authorization, validation, secret handling, telemetry privacy, error propagation, database efficiency, and coverage.
Best Practices
- Adapt examples to the repository patterns and verify every referenced dependency.
- Require validation, authorization, error handling, and tests for every endpoint.
- Review secret defaults and monitoring fields before production deployment.
Avoid
- Do not place business logic or direct database access in route handlers.
- Do not copy project-specific paths, credentials, or telemetry settings unchanged.
- Do not treat example code as production-ready without security and integration review.
Frequently Asked Questions
Which backend stack does this skill target?
Can it generate a complete service?
Does it replace framework documentation?
Can I use it without Prisma?
Does it cover security?
How should I use the examples?
Developer Details
Author
BrianDai22License
MIT
Skillstore revision
r2
Version notice
The author did not declare a version.
Repository
https://github.com/BrianDai22/concetrateaiquiz/tree/main/.claude/skills/backend-dev-guidelinesRef
a39a91716eadede5f4cdefd78178fed4e837a128
Maintenance freshness
7/24/2026
Usage
5 downloads ยท 514 views
File structure
๐ resources/
๐ async-and-errors.md
๐ complete-examples.md
๐ configuration.md
๐ database-patterns.md
๐ middleware-guide.md
๐ routing-and-controllers.md
๐ services-and-repositories.md
๐ testing-guide.md
๐ SKILL.md