oma-backend
Implement server APIs, authentication, and application data access.
Install / Use
npx skills add first-fluke/oh-my-agent --skill oma-backendInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Data & AnalyticsSupported Platforms
Our assessment of oma-backend
oma-backend scores 85/100 on our quality scale, 405th of 585 Data & Analytics skills we index.
Its SKILL.md is 10.0 KB long, well organised into 32 sections with 1 code example: a thorough specification that gives an agent plenty to work with.
With 1,324 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 11 days ago, so oma-backend is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit β read the skill file before letting an agent act on it.
oma-backend compared with similar skills
All 4 of these similar skills score higher than oma-backend; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| oma-backend (this skill)by first-fluke | 85 | 1.3k | 11d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 91.2k | 19d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.4k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.7k | today | MCP Server |
| crawl4aiby unclecode | 100 | 84.8k | today | MCP Server |
Frequently asked questions
- How do I install oma-backend?
- Run
npx skills add first-fluke/oh-my-agent --skill oma-backend. The install tabs above show the steps for each supported agent. - Which AI agents does oma-backend work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is oma-backend safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is oma-backend still maintained?
- The repository was last updated 11 days ago, so oma-backend is actively maintained.
Skill content
View source on GitHubname: oma-backend description: Implement server APIs, authentication, and application data access. Schema modeling and query tuning use oma-db.
Backend Agent - API & Server Specialist
Scheduling
Goal
Implement or review backend APIs, authentication, database integration, server-side business logic, and migrations using the project's existing backend stack and clean architecture boundaries.
Intent signature
- User asks for API, endpoint, REST, GraphQL, auth, server, migration, repository, service, router, or background job work.
- User needs backend code that coordinates validation, business logic, persistence, transactions, and backing services.
When to use
- Building REST APIs or GraphQL endpoints
- Database design and migrations
- Authentication and authorization
- Server-side business logic
- Background jobs and queues
When NOT to use
- Frontend UI -> use Frontend Agent
- Mobile-specific code -> use Mobile Agent
Expected inputs
- Target feature, endpoint, migration, auth flow, or server behavior
- Existing backend stack files such as manifests, routes, services, models, and database config
- API contracts, schemas, validation rules, and persistence requirements
- Required verification commands or project conventions
Expected outputs
- Backend code changes in router, service, repository, model, migration, or test files
- Validated inputs, safe queries, transaction boundaries, and error handling
- Verification results from the execution checklist
Dependencies
- Project stack manifests and existing backend conventions
resources/execution-protocol.md,resources/checklist.md, andresources/orm-reference.md
- Optional
stack/stack.yaml,stack/tech-stack.md, snippets, and API templates
- Database, queue, cache, mail, auth, or external API resources configured through environment or secret managers
Control-flow features
- Branches by detected stack, ORM/query pattern, auth requirement, migration impact, and transaction scope
- Reads and writes codebase files
- May touch local database migrations or generated code
- Must not hardcode secrets or share unsafe ORM lifecycle objects across concurrent work
Structural Flow
Entry
- Detect the backend stack from project files first.
- Identify affected router, service, repository, model, migration, and test boundaries.
- Load stack-specific references only when needed.
Scenes
- PREPARE: Determine stack, architecture boundaries, and acceptance criteria.
- ACQUIRE: Read existing routes, services, repositories, models, schemas, and config.
- ACT: Implement backend changes with validation, business logic, persistence, and tests.
- VERIFY: Run relevant lint, type, test, migration, and checklist commands.
- FINALIZE: Report changed behavior, verification, and unresolved risks.
Transitions
- If stack files exist, follow them before generic guidance.
- If ORM performance, relationship loading, transactions, or N+1 risk appears, use
resources/orm-reference.md. - If database schema impact is primary and API work is secondary, coordinate with
oma-db. - If auth server setup touches DB adapters or server libraries, keep it in backend scope.
Failure and recovery
- If stack cannot be determined, ask the user or suggest running
/stack-set. - If verification fails, fix root cause before handoff.
- If required secrets or services are unavailable, document the blocker and keep code configurable.
Exit
- Success: backend change is implemented, tested, and aligned with local architecture.
- Partial success: blocker, missing dependency, or verification gap is explicit.
Logical Operations
Actions
| Action | SSL primitive | Evidence |
|--------|---------------|----------|
| Detect stack and conventions | READ | Manifests, stack files, existing code |
| Select implementation boundary | SELECT | Router/service/repository pattern |
| Validate inputs and schemas | VALIDATE | Stack validation library |
| Implement business logic | WRITE | Service layer code |
| Implement persistence | WRITE | Repository/model/migration code |
| Call external/backing services | CALL_TOOL | DB, queue, cache, auth, or API clients |
| Run verification | CALL_TOOL | Tests, typecheck, lint, migrations |
| Report result | NOTIFY | Final summary |
Tools and instruments
- Project language/framework toolchain
- ORM or database client
- Test, lint, typecheck, and migration commands
- Stack-specific templates and snippets when present
Canonical workflow path
Use the configured code-intelligence provider to locate files and inspect symbols
or content. For Serena, use find_file, search_for_pattern,
get_symbols_overview, and find_symbol. Native search is limited to the
provider exclusions and non-code paths permitted by the project's search policy.
Then run the project's discovered verification commands, usually lint/typecheck/tests and migrations when schema changes are involved. Prefer stack/stack.yaml verify: commands when present.
Resource scope
| Scope | Resource target |
|-------|-----------------|
| CODEBASE | Backend source, tests, schemas, migrations |
| LOCAL_FS | Stack references and generated artifacts |
| PROCESS | Test, lint, typecheck, migration commands |
| CREDENTIALS | Environment-managed DB URLs, API keys, secrets |
| NETWORK | External APIs or backing services when required |
Preconditions
- Target behavior and affected backend boundary are identifiable.
- Project stack and verification commands can be inferred or are provided.
- Required credentials remain outside source code.
Effects and side effects
- Mutates backend source files, tests, and possibly migrations.
- May change database schema, API behavior, auth behavior, or service contracts.
- May require generated clients or migration artifacts.
Guardrails
Apply framework, library, architecture, and data-model defaults only when the target project has no established choice. Scoped edits do not authorize a stack migration or unrelated infrastructure.
- DRY (Don't Repeat Yourself): Business logic in
Service, data access logic inRepository - SOLID:
- Single Responsibility: Classes and functions should have one responsibility
- Dependency Inversion: Use your framework's DI mechanism
- KISS: Keep it simple and clear
Architecture Pattern
Router (HTTP) β Service (Business Logic) β Repository (Data Access) β Models
Repository Layer
- Encapsulate DB CRUD and query logic
- No business logic, return ORM entities
Service Layer
- Business logic, Repository composition, external API calls
- Business decisions only here
Router Layer
- Receive HTTP requests, input validation, call Service, return response
- No business logic, inject Service via DI
Core Rules
- Clean architecture: router β service β repository β models
- No business logic in route handlers
- All inputs validated with your stack's validation library
- Parameterized queries only (never string interpolation)
- JWT + Argon2id for auth (bcrypt acceptable for legacy compatibility); rate limit auth endpoints
- Async where supported; type annotations on all signatures
- Custom exceptions via centralized error module (not raw HTTP exceptions)
- Explicit ORM loading strategy: do not rely on default relation loading when query shape matters
- Explicit transaction boundaries: group one business operation into one request/service-scoped unit of work
- Safe ORM lifecycle: do not share mutable ORM session/entity manager/client objects across concurrent work unless the ORM explicitly supports it
- Validate required configuration: DB URLs, API keys, secrets, and feature flags come from environment variables or secret managers. Missing credentials fail clearly in default and production modes. Deterministic fixtures require an explicitly selected test/demo mode; label simulated results and never treat simulated payment, authentication, mail, or other effects as completed real operations.
- Stateless services: no in-memory session or user state between requests; use external stores (DB, Redis, cache) for shared state
- Backing services as resources: DB, queue, cache, mail are swappable attached resources connected via config; Repository layer must not assume a specific instance
Stack Detection
- Project files first: Read existing code, package manifests (pyproject.toml, package.json, Cargo.toml, go.mod, pom.xml, etc.) to determine the tech stack
- stack/ second: If
stack/exists, use it as supplementary reference for coding conventions and snippet templates - Neither exists: Ask the user or suggest running
/stack-set
Stack-Specific Reference
<!-- oma-docs:ignore-start -->- Stack manifest (SSOT):
stack/stack.yaml: structured declaration (language,framework,orm) andverify:contract consumed byoma verify agent backend. Schema:variants/stack.schema.json. - Tech stack narrative:
stack/tech-stack.md: human-readable reference only;stack.yamlwins on conflict. - Code snippets (copy-paste ready):
stack/snippets.md - API template:
stack/api-template.*
References
-
Local code tools:
../_shared/core/code-intelligence.md(code search/navigation) -
Execution steps (follow for the selected task):
resources/execution-protocol.md -
Checklist (run before handoff):
resources/checklist.md -
ORM reference:
resources/orm-reference.md -
Error recovery:
resources/error-playbook.md -
Context loading:
../_shared/core/context-loading.md -
Clarification:
../_shared/core/clarification-protocol.md -
Context budget:
../_shared/core/context-budget.md -
Lessons learned:
../_shared/core/lessons-learned.md(matching prior failure or requested retrospective) -
Observability handoff:
../oma-observability/SKILL.mdΒ§Integrations β propagators/baggage, span conventions, log correlation, PII redaction
Related Skills
Agent-Reach
91.2kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu β one CLI, zero API fees.
headroom
74.4kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
85.7kπ·οΈ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
crawl4ai
84.8kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit β see the Safety scan above for what the skill file itself contains.
