Claude-skill-registry backend-core

install
source · Clone the upstream repo
git clone https://github.com/majiayu000/claude-skill-registry
Claude Code · Install into ~/.claude/skills/
T=$(mktemp -d) && git clone --depth=1 https://github.com/majiayu000/claude-skill-registry "$T" && mkdir -p ~/.claude/skills && cp -r "$T/skills/data/backend-core" ~/.claude/skills/majiayu000-claude-skill-registry-backend-core && rm -rf "$T"
manifest: skills/data/backend-core/SKILL.md
source content

Backend Core Patterns

Quick Reference

TopicWhen to UseReference
API DesignREST/GraphQL/gRPC endpointsapi-design.md
AuthenticationJWT, OAuth, sessions, magic linksauthentication.md
SecurityInput validation, OWASP, rate limitingsecurity.md
DatabasesSchema design, migrations, queriesdatabases.md

API Design Decision Tree

What type of API?
├─ Public API → REST + OpenAPI spec
├─ Internal microservices → gRPC (performance) or REST (simplicity)
├─ Real-time → WebSocket or SSE
└─ Complex queries → GraphQL

Auth Decision Tree

Auth method?
├─ SPA/Mobile → JWT (access + refresh tokens)
├─ Server-rendered → Session cookies
├─ Third-party login → OAuth 2.0 / OIDC
├─ Passwordless → Magic link (email) or WebAuthn
└─ API-to-API → API keys or mTLS

Security Essentials

Always:

  • Validate all inputs at boundaries
  • Use parameterized queries (never string concat SQL)
  • Hash passwords with bcrypt/argon2 (cost ≥ 10)
  • HTTPS everywhere, HSTS headers
  • Rate limit auth endpoints

Never:

  • Store secrets in code or git
  • Trust client-side validation alone
  • Log sensitive data (passwords, tokens, PII)
  • Use MD5/SHA1 for passwords

Database Patterns

Schema design:
├─ Start normalized (3NF)
├─ Denormalize only for proven bottlenecks
├─ Always have created_at, updated_at
├─ Use UUIDs for public IDs, integers for internal FKs
└─ Soft delete (deleted_at) for important data

Anti-patterns

Don'tDo Instead
N+1 queriesEager load / batch queries
SELECT *Select only needed columns
No indexes on WHERE/JOIN columnsAdd indexes
Storing files in DBUse object storage (S3, R2)
God objectsBounded contexts, single responsibility