All skills
jakeschincariol avatar

/replica-backend

@77c9436

Builds the backend of an app clone: auth, database migrations and access rules, payments with Stripe, email, background jobs and third-party integrations through official APIs only, plus a security checklist. Use when the user says "add login", "set up auth", "wire up the database", "add payments", "connect Stripe", "add Google Calendar", "send emails", "backend for my clone", or when /replica-build is running on fake data.

Use this Skill: https://skilld.dev/gh/jakeschincariol/replica-skill/replica-backend

Nothing lands on disk. Nothing to clean up.

Fork this Skill

Edit a local copy. It keeps the author and licence.

SKILL.md

≈111 tokens for metadata: the name and description. ≈875 when used: this file.

Description uses 5.6% of example budget

Before choosing a Skill, your Agent reads its name and description. All available Skills share that space.

  • A shorter description leaves more room for other Skills. This entry exceeds our 1% size suggestion.

In our Claude Code example, all Skill names and descriptions share 8,000 characters. This Skill uses ≈445 characters, or 5.6%.

The 1% threshold is a size suggestion. Longer descriptions can still fit.

Your model, settings, and other Skills decide how much text your Agent can read.

Example settings and source

The example uses a 200k-token context and default Claude Code settings. The count includes the name, description, separators, and when_to_use when present. Codex also counts local file paths.

Skit's source and limits: Codex 0.160.1, Claude Code 2.1.292.

replica-backend

Reads replica/architecture.md. Writes migrations and server code, and keeps replica/backend.md (checklist below) up to date.

The rules

  • Official, public APIs only, with the user's own keys. Never call the original app's private endpoints, never reuse its OAuth client, never proxy through it.
  • The user creates accounts and keys. Claude never signs up for services, never types a password, card or live key. The user creates the Stripe, Supabase, Resend or Google Cloud project and puts keys in .env.local. Claude writes .env.example with every variable name and no values.
  • Test mode first. Stripe test keys and test cards until replica-deploy.

Auth

  • Email sign up with verification, password reset, magic link if the original has it. OAuth (Google, Apple) with the user's own developer apps.
  • Sessions: http-only secure cookies. Sign out everywhere.
  • Roles and teams if the recon map has them: owner, admin, member, with one function that answers "can this user do this to this record".
  • Account deletion that actually deletes. Apple requires it for apps with sign up.

Database

  • Migrations from architecture.md, checked in, run by a script.
  • Access rules on every table: row level security policies on Supabase, or the authorisation function called in every query. Test it: a second user must get nothing back.
  • Seed script with realistic fake data (no real people).
  • Backups on (the host's daily backups count, check they are enabled).

Payments

  • Stripe Checkout for sign up to a plan, the Customer Portal for changes and cancelling. Do not build card forms.
  • Webhooks: verify the signature, store the event id, make every handler idempotent (Stripe retries). Handle checkout.session.completed, customer.subscription.updated, customer.subscription.deleted, invoice.payment_failed.
  • Subscription status lives in your database, updated by webhooks, read by your app. Never trust the client.
  • Cancelling is one click. Hard-to-cancel billing is a top complaint about most apps, and in many places it is illegal.

Email and jobs

  • Transactional email through Resend or Postmark from your own domain. Templates written fresh.
  • Jobs for anything time-based (reminders, digests, sync, cleanup) with retries and a dead-letter log. Times in UTC, shown in the user's zone.

Integrations

For each integration in the feature matrix: the official API, the OAuth scopes needed (fewest possible), the provider's review process, rate limits. Google scopes like Calendar need Google's OAuth verification before public launch, which takes weeks. Start it early and write that in backend.md.

Security checklist

  • secrets only in env vars, .env* in .gitignore, nothing in client bundles
  • input validated on the server (zod or similar) on every route
  • authorisation checked on every read and write, tested with a second user
  • rate limits on auth, sign up, and anything that sends email or SMS
  • webhooks verify signatures
  • uploads: size and type limits, served from a separate domain or bucket
  • no user data in URLs or logs
  • dependencies audited (npm audit)
  • privacy policy lists every processor (Stripe, Resend, host, analytics)

Output

Working auth, database, payments in test mode, email and the integrations, .env.example, replica/backend.md with the checklist ticked, feature matrix rows updated. Next: /replica-test.

Source: SKILL.md on GitHub

No rule matched.

skilld matched fixed text patterns in SKILL.md and file names. Patterns miss obfuscated code.

skilld run checks every file with the same patterns. It asks for approval before it loads a Skill with a behavior marked Needs approval.

No alerts4d3 checks · Risk SAFE
  • Gen Agent Trust Hub4d

    The skill provides a set of secure development practices for generating backend code. It emphasizes credential safety, official API usage, and includes a comprehensive security checklist for authentication, database access, and payment processing.

  • Socket4d

    No alerts

  • Snyk4d

    Risk: LOW · No issues

Signed by skilld at 77c9436. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 44 minutes ago.

Activeupdated 5 days ago

README badge

README badge for jakeschincariol/replica-skill/replica-backend