跳到正文
FunCoding

搜索

搜索文档、Skill 和 MCP

replica-backend

Builds the backend of an app clone: auth, database migrations and access rules, payments with Stripe, email, background jobs and third-party integrations through official APIs only, plus a security checklist. Use when the user says "add login", "set up auth", "wire up the database", "add payments", "connect Stripe", "add Google Calendar", "send emails", "backend for my clone", or when /replica-build is running on fake data.

数据库与数据998replica-backend/SKILL.md

安装

把这段话发给 Claude Code、Codex 或 Cursor。智能体会先检查安全性,你确认后才安装。

读取 https://funcoding.ai/skills/jakeschincariol/replica-skill/replica-backend/install.md ,按里面的步骤帮我安装这个 Skill。

SKILL.md

replica-backend

Reads replica/architecture.md. Writes migrations and server code, and keeps replica/backend.md (checklist below) up to date.

The rules

  • Official, public APIs only, with the user's own keys. Never call the original app's private endpoints, never reuse its OAuth client, never proxy through it.
  • The user creates accounts and keys. Claude never signs up for services, never types a password, card or live key. The user creates the Stripe, Supabase, Resend or Google Cloud project and puts keys in .env.local. Claude writes .env.example with every variable name and no values.
  • Test mode first. Stripe test keys and test cards until replica-deploy.

Auth

  • Email sign up with verification, password reset, magic link if the original has it. OAuth (Google, Apple) with the user's own developer apps.
  • Sessions: http-only secure cookies. Sign out everywhere.
  • Roles and teams if the recon map has them: owner, admin, member, with one function that answers "can this user do this to this record".
  • Account deletion that actually deletes. Apple requires it for apps with sign up.

Database

  • Migrations from architecture.md, checked in, run by a script.
  • Access rules on every table: row level security policies on Supabase, or the authorisation function called in every query. Test it: a second user must get nothing back.
  • Seed script with realistic fake data (no real people).
  • Backups on (the host's daily backups count, check they are enabled).

Payments

  • Stripe Checkout for sign up to a plan, the Customer Portal for changes and cancelling. Do not build card forms.
  • Webhooks: verify the signature, store the event id, make every handler idempotent (Stripe retries). Handle checkout.session.completed, customer.subscription.updated, customer.subscription.deleted, invoice.payment_failed.
  • Subscription status lives in your database, updated by webhooks, read by your app. Never trust the client.
  • Cancelling is one click. Hard-to-cancel billing is a top complaint about most apps, and in many places it is illegal.

Email and jobs

  • Transactional email through Resend or Postmark from your own domain. Templates written fresh.
  • Jobs for anything time-based (reminders, digests, sync, cleanup) with retries and a dead-letter log. Times in UTC, shown in the user's zone.

Integrations

For each integration in the feature matrix: the official API, the OAuth scopes needed (fewest possible), the provider's review process, rate limits. Google scopes like Calendar need Google's OAuth verification before public launch, which takes weeks. Start it early and write that in backend.md.

Security checklist

  • secrets only in env vars, .env* in .gitignore, nothing in client bundles
  • input validated on the server (zod or similar) on every route
  • authorisation checked on every read and write, tested with a second user
  • rate limits on auth, sign up, and anything that sends email or SMS
  • webhooks verify signatures
  • uploads: size and type limits, served from a separate domain or bucket
  • no user data in URLs or logs
  • dependencies audited (npm audit)
  • privacy policy lists every processor (Stripe, Resend, host, analytics)

Output

Working auth, database, payments in test mode, email and the integrations, .env.example, replica/backend.md with the checklist ticked, feature matrix rows updated. Next: /replica-test.

相似的 Skill

xlsx
anthropics/skills180k

xlsx

Use this skill any time a spreadsheet file is the primary input or output. This means any task where the user wants to: open, read, edit, or fix an existing .xlsx, .xlsm, .xltx, .csv, or .tsv file (e.g., adding columns, computing formulas, formatting, charting, cleaning messy data); create a new spreadsheet from scratch or from other data sources; or convert between tabular file formats. Trigger especially when the user references a spreadsheet file by name or path — even casually (like "the xlsx in my downloads") — and wants something done to it or produced from it. Also trigger for cleaning or restructuring messy tabular data files (malformed rows, misplaced headers, junk data) into proper spreadsheets. The deliverable must be a spreadsheet file. Do NOT trigger when the primary deliverable is a Word document, HTML report, standalone Python script, database pipeline, or Google Sheets API integration, even if tabular data is involved.

数据库与数据

deprecation-and-migration
addyosmani/agent-skills103k

deprecation-and-migration

Manages deprecation and migration. Use when removing old systems, APIs, or features. Use when migrating users from one implementation to another. Use when migrating a database schema in production, such as renaming or dropping a column without downtime (expand/contract). Use when deciding whether to maintain or sunset existing code.

数据库与数据

host-observer
thedotmack/claude-mem98k

host-observer

Use this when fulfilling claude-mem observer jobs on Grok Bot: reply only skip_summary or one full observation XML, never prose.

数据库与数据

babysit
thedotmack/claude-mem98k

babysit

Watch a pull request or review cycle until it is ready to merge. Use when asked to babysit, monitor, or keep checking PR comments, reviews, and CI until all actionable issues are resolved.

数据库与数据

mem-search
thedotmack/claude-mem98k

mem-search

Search claude-mem's persistent cross-session memory database. Use when user asks "did we already solve this?", "how did we do X last time?", or needs work from previous sessions.

数据库与数据

Agent Cost Report
thedotmack/claude-mem98k

Agent Cost Report

Believable agent cost report for any period, default the last 7 full days PT, not counting today. Measured tokens from Claude Code transcripts priced at OpenRouter list prices (ESTIMATED), measured provider spend when a sanctioned source exists, note-taker cost separate, Timing-style HTML/PDF plus report.json, line-items.csv, evidence.json.

数据库与数据