All skills
debabratasaha-dev avatar

/backend-engineer

@a1f81fa

Professional backend engineering for production-grade APIs, services, workers, databases, authentication, authorization, integrations, queues, observability, testing, reliability, and security. Use when the agent needs to build, improve, review, debug, or harden backend systems in Node.js, Python, Go, Java, .NET, Ruby, PHP, SQL, NoSQL, REST, GraphQL, WebSockets, event-driven systems, or similar backend stacks. Triggers on requests to build APIs, services, workers, webhook handlers, auth systems, database layers, background jobs, queues, cron tasks, billing flows, or server-side features. Also triggers on requests to fix slow queries, race conditions, deadlocks, failing tests, deployment issues, or to review backend code for security, correctness, and reliability.

Use this Skill: https://skilld.dev/gh/debabratasaha-dev/techskills/backend-engineer

This session only. Nothing lands on disk.

assetsbackend-starterexamplesconsistent-errors.md

≈435 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Consistent Error Responses

Return predictable error shapes across all endpoints. Clients should parse one error format.

Standard Error Shape

{
  "error": {
    "code": "MACHINE_READABLE_CODE",
    "message": "Human-readable description",
    "details": []
  }
}

Error Codes

HTTP Status Error Code When
400 VALIDATION_ERROR Invalid input
401 UNAUTHENTICATED Missing or invalid auth
403 FORBIDDEN Authenticated but not authorized
404 NOT_FOUND Resource does not exist
409 CONFLICT Duplicate or state conflict
429 RATE_LIMITED Too many requests
500 INTERNAL_ERROR Unexpected server error

Pattern

// Pseudocode — central error handler middleware

function errorHandler(error, request, response):
  if error is ValidationError:
    return 400, formatError("VALIDATION_ERROR", error.message, error.fieldErrors)
  if error is AuthError:
    return 401, formatError("UNAUTHENTICATED", "Invalid credentials")
  if error is ForbiddenError:
    return 403, formatError("FORBIDDEN", "Access denied")
  if error is NotFoundError:
    return 404, formatError("NOT_FOUND", error.message)
  // Unexpected errors
  log.error(error, { requestId: request.id })
  return 500, formatError("INTERNAL_ERROR", "Something went wrong")

function formatError(code, message, details = null):
  return { error: { code, message, details } }

Rules

  • Never leak stack traces, SQL errors, or file paths in production responses.
  • Log full error details server-side with request ID.
  • Return 404 (not 403) for missing resources to prevent enumeration.
  • Include requestId in error response for support debugging.

Source: SKILL.md on GitHub

No alerts18d3 checks · Risk SAFE
  • Gen Agent Trust Hub18d

    The skill provides comprehensive, high-quality engineering guidelines and references for backend development. It focuses on security best practices, such as input validation, authorization, and secure secret handling, without any detected malicious patterns.

  • Socket18d

    No alerts

  • Snyk18d

    Risk: LOW · No issues

Signed by skilld at a1f81fa. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 4 months ago
metadata
{
  "version": "1.0.0"
}

README badge

README badge for debabratasaha-dev/techskills/backend-engineer