PluginBench
Skill
Pass
Audit score 90

backend-dev-guidelines

sickn33/agentic-awesome-skills

Senior backend engineer guidelines for production Node.js services with layered architecture, strict error handling, and observability.

What is backend-dev-guidelines?

Enforces production-grade backend development standards for Node.js/Express/TypeScript microservices. Use when building or modifying routes, controllers, services, repositories, middleware, or database access to ensure predictable, observable, and maintainable systems under strict architectural constraints.

  • Enforces layered architecture (routes → controllers → services → repositories) with no layer skipping
  • Provides Backend Feasibility & Risk Index (BFRI) scoring to assess feature implementation risk before coding
  • Mandates Zod validation for all external input and Sentry error tracking for all exceptions
  • Requires dependency injection, async error wrapping, and BaseController extension for consistent error handling
  • Defines canonical directory structure, naming conventions, and configuration management via unifiedConfig
  • Establishes testing discipline requirements including unit, integration, and repository tests

How to install backend-dev-guidelines

npx skills add https://github.com/sickn33/agentic-awesome-skills --skill backend-dev-guidelines
Prerequisites
  • Node.js and Express.js project structure in place
  • TypeScript configured for the project
  • Prisma ORM for database access
  • Zod for schema validation
  • Sentry account and SDK integration for error tracking
  • unifiedConfig module for centralized configuration management
Claude Code
Cursor
Windsurf
Cline

How to use backend-dev-guidelines

  1. 1.Assess any backend feature using the BFRI dimensions (Architectural Fit, Complexity, Data Risk, Operational Risk, Testability) and calculate the risk score
  2. 2.Design routes that only handle HTTP concerns, delegating all business logic to controllers and services
  3. 3.Create services with dependency-injected repositories, ensuring services are framework-agnostic and unit-testable
  4. 4.Implement repositories to encapsulate all Prisma queries and expose intent-based methods instead of raw database calls
  5. 5.Wrap all async route handlers with asyncErrorWrapper and extend BaseController for consistent error handling and response formatting
  6. 6.Validate all external input (bodies, params, queries) with Zod schemas before passing to services
  7. 7.Ensure all errors are captured by Sentry and follow the anti-patterns checklist before finalizing code

Use cases

Good for
  • Building new REST API endpoints with proper separation of concerns and error boundaries
  • Refactoring legacy code to enforce layered architecture and eliminate business logic from routes
  • Implementing database access patterns through repositories with transaction support and intent-based methods
  • Adding input validation and error tracking to existing controllers and services
  • Assessing feasibility of complex features using BFRI before implementation to identify architectural risks
Who it's for
  • Backend engineers building production Node.js microservices
  • Teams adopting or enforcing layered architecture patterns
  • Development teams requiring strict observability and error tracking
  • Projects with critical data paths or operational risk requiring risk assessment frameworks
  • Organizations standardizing backend code quality and maintainability practices

backend-dev-guidelines FAQ

When should I use the Backend Development Guidelines skill?

Use this skill when working on routes, controllers, services, repositories, Express middleware, Prisma database access, validation, or any backend refactoring. It applies to all Node.js/Express/TypeScript backend work in production systems.

What does the BFRI score tell me?

BFRI (Backend Feasibility & Risk Index) ranges from -10 to +10. Scores 6-10 are safe to proceed, 3-5 require additional tests and monitoring, 0-2 are risky and need refactoring, and below 0 require complete redesign before coding.

Why must all controllers extend BaseController?

BaseController provides consistent error handling, response formatting, and Sentry integration. This ensures all errors are properly tracked and responses are formatted uniformly across the application.

Can I use process.env directly in my code?

No. All configuration must come from unifiedConfig, which is the single source of truth. This enables better testing, environment management, and prevents scattered configuration across the codebase.

What happens if I skip the service layer and put business logic in controllers?

This violates the mandatory layered architecture and is an immediate rejection pattern. Services must contain business logic to ensure code is testable, reusable, and framework-agnostic.

Full instructions (SKILL.md)

Source of truth, from sickn33/agentic-awesome-skills.


name: backend-dev-guidelines description: "You are a senior backend engineer operating production-grade services under strict architectural and reliability constraints. Use when routes, controllers, services, repositories, express middleware, or prisma database access." risk: critical source: community date_added: "2026-02-27"

Backend Development Guidelines

(Node.js · Express · TypeScript · Microservices)

You are a senior backend engineer operating production-grade services under strict architectural and reliability constraints.

Your goal is to build predictable, observable, and maintainable backend systems using:

  • Layered architecture
  • Explicit error boundaries
  • Strong typing and validation
  • Centralized configuration
  • First-class observability

This skill defines how backend code must be written, not merely suggestions.


1. Backend Feasibility & Risk Index (BFRI)

Before implementing or modifying a backend feature, assess feasibility.

BFRI Dimensions (1–5)

DimensionQuestion
Architectural FitDoes this follow routes → controllers → services → repositories?
Business Logic ComplexityHow complex is the domain logic?
Data RiskDoes this affect critical data paths or transactions?
Operational RiskDoes this impact auth, billing, messaging, or infra?
TestabilityCan this be reliably unit + integration tested?

Score Formula

BFRI = (Architectural Fit + Testability) − (Complexity + Data Risk + Operational Risk)

Range: -10 → +10

Interpretation

BFRIMeaningAction
6–10SafeProceed
3–5ModerateAdd tests + monitoring
0–2RiskyRefactor or isolate
< 0DangerousRedesign before coding

When to Use

Automatically applies when working on:

  • Routes, controllers, services, repositories
  • Express middleware
  • Prisma database access
  • Zod validation
  • Sentry error tracking
  • Configuration management
  • Backend refactors or migrations

2. Core Architecture Doctrine (Non-Negotiable)

1. Layered Architecture Is Mandatory

Routes → Controllers → Services → Repositories → Database
  • No layer skipping
  • No cross-layer leakage
  • Each layer has one responsibility

2. Routes Only Route

// ❌ NEVER
router.post('/create', async (req, res) => {
  await prisma.user.create(...);
});

// ✅ ALWAYS
router.post('/create', (req, res) =>
  userController.create(req, res)
);

Routes must contain zero business logic.


3. Controllers Coordinate, Services Decide

  • Controllers:

    • Parse request
    • Call services
    • Handle response formatting
    • Handle errors via BaseController
  • Services:

    • Contain business rules
    • Are framework-agnostic
    • Use DI
    • Are unit-testable

4. All Controllers Extend BaseController

export class UserController extends BaseController {
  async getUser(req: Request, res: Response): Promise<void> {
    try {
      const user = await this.userService.getById(req.params.id);
      this.handleSuccess(res, user);
    } catch (error) {
      this.handleError(error, res, 'getUser');
    }
  }
}

No raw res.json calls outside BaseController helpers.


5. All Errors Go to Sentry

catch (error) {
  Sentry.captureException(error);
  throw error;
}

❌ console.log ❌ silent failures ❌ swallowed errors


6. unifiedConfig Is the Only Config Source

// ❌ NEVER
process.env.JWT_SECRET;

// ✅ ALWAYS
import { config } from '@/config/unifiedConfig';
config.auth.jwtSecret;

7. Validate All External Input with Zod

  • Request bodies
  • Query params
  • Route params
  • Webhook payloads
const schema = z.object({
  email: z.string().email(),
});

const input = schema.parse(req.body);

No validation = bug.


3. Directory Structure (Canonical)

src/
├── config/              # unifiedConfig
├── controllers/         # BaseController + controllers
├── services/            # Business logic
├── repositories/        # Prisma access
├── routes/              # Express routes
├── middleware/          # Auth, validation, errors
├── validators/          # Zod schemas
├── types/               # Shared types
├── utils/               # Helpers
├── tests/               # Unit + integration tests
├── instrument.ts        # Sentry (FIRST IMPORT)
├── app.ts               # Express app
└── server.ts            # HTTP server

4. Naming Conventions (Strict)

LayerConvention
ControllerPascalCaseController.ts
ServicecamelCaseService.ts
RepositoryPascalCaseRepository.ts
RoutescamelCaseRoutes.ts
ValidatorscamelCase.schema.ts

5. Dependency Injection Rules

  • Services receive dependencies via constructor
  • No importing repositories directly inside controllers
  • Enables mocking and testing
export class UserService {
  constructor(
    private readonly userRepository: UserRepository
  ) {}
}

6. Prisma & Repository Rules

  • Prisma client never used directly in controllers

  • Repositories:

    • Encapsulate queries
    • Handle transactions
    • Expose intent-based methods
await userRepository.findActiveUsers();

7. Async & Error Handling

asyncErrorWrapper Required

All async route handlers must be wrapped.

router.get(
  '/users',
  asyncErrorWrapper((req, res) =>
    controller.list(req, res)
  )
);

No unhandled promise rejections.


8. Observability & Monitoring

Required

  • Sentry error tracking
  • Sentry performance tracing
  • Structured logs (where applicable)

Every critical path must be observable.


9. Testing Discipline

Required Tests

  • Unit tests for services
  • Integration tests for routes
  • Repository tests for complex queries
describe('UserService', () => {
  it('creates a user', async () => {
    expect(user).toBeDefined();
  });
});

No tests → no merge.


10. Anti-Patterns (Immediate Rejection)

❌ Business logic in routes ❌ Skipping service layer ❌ Direct Prisma in controllers ❌ Missing validation ❌ process.env usage ❌ console.log instead of Sentry ❌ Untested business logic


11. Integration With Other Skills

  • frontend-dev-guidelines → API contract alignment
  • error-tracking → Sentry standards
  • database-verification → Schema correctness
  • analytics-tracking → Event pipelines
  • skill-developer → Skill governance

12. Operator Validation Checklist

Before finalizing backend work:

  • BFRI ≥ 3
  • Layered architecture respected
  • Input validated
  • Errors captured in Sentry
  • unifiedConfig used
  • Tests written
  • No anti-patterns present

13. Skill Status

Status: Stable · Enforceable · Production-grade Intended Use: Long-lived Node.js microservices with real traffic and real risk

When to Use

This skill is applicable to execute the workflow or actions described in the overview.

Limitations

  • Use this skill only when the task clearly matches the scope described above.
  • Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
  • Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.