All skills
debabratasaha-dev avatar

/backend-engineer

@a1f81fa

Professional backend engineering for production-grade APIs, services, workers, databases, authentication, authorization, integrations, queues, observability, testing, reliability, and security. Use when the agent needs to build, improve, review, debug, or harden backend systems in Node.js, Python, Go, Java, .NET, Ruby, PHP, SQL, NoSQL, REST, GraphQL, WebSockets, event-driven systems, or similar backend stacks. Triggers on requests to build APIs, services, workers, webhook handlers, auth systems, database layers, background jobs, queues, cron tasks, billing flows, or server-side features. Also triggers on requests to fix slow queries, race conditions, deadlocks, failing tests, deployment issues, or to review backend code for security, correctness, and reliability.

Use this Skill: https://skilld.dev/gh/debabratasaha-dev/techskills/backend-engineer

This session only. Nothing lands on disk.

assetsbackend-starterexampleswebhook-handler.md

≈334 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Webhook Handler Pattern

Receive, verify, and process webhooks from external services safely.

Pattern

// Pseudocode — Stripe-style webhook handler

function handleWebhook(request):
  // 1. Verify signature
  signature = request.headers["X-Signature"]
  payload = request.rawBody
  if !verifyHmacSha256(WEBHOOK_SECRET, payload, signature):
    return 401, { error: "Invalid signature" }

  // 2. Check timestamp freshness (prevent replay)
  event = parseJson(payload)
  if event.timestamp < now() - 5_minutes:
    return 400, { error: "Event too old" }

  // 3. Idempotency check
  if db.exists("webhook_events", { eventId: event.id }):
    return 200, { status: "already_processed" }

  // 4. Store event before processing
  db.insert("webhook_events", {
    eventId: event.id,
    type: event.type,
    payload: event,
    receivedAt: now(),
    status: "pending"
  })

  // 5. Return 200 immediately
  // 6. Process asynchronously
  queue.publish("webhook_processing", { eventId: event.id })
  return 200, { status: "accepted" }

Rules

  • Always verify signatures with constant-time comparison.
  • Return 200 quickly. Process heavy work in background.
  • Store raw event for debugging and replay.
  • Make processing idempotent — same event ID processed only once.
  • Log: event type, event ID, processing result.

Source: SKILL.md on GitHub

No alerts18d3 checks · Risk SAFE
  • Gen Agent Trust Hub18d

    The skill provides comprehensive, high-quality engineering guidelines and references for backend development. It focuses on security best practices, such as input validation, authorization, and secure secret handling, without any detected malicious patterns.

  • Socket18d

    No alerts

  • Snyk18d

    Risk: LOW · No issues

Signed by skilld at a1f81fa. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 4 months ago
metadata
{
  "version": "1.0.0"
}

README badge

README badge for debabratasaha-dev/techskills/backend-engineer