Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add agents/cenconq25/claude-code-app-studio/backend-engineergit clone --depth 1 https://github.com/cenconq25/claude-code-app-studioWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00056 | $0.01247 |
| Opus 5 | $0.00028 | $0.00624 |
| Sonnet 5 | $0.00011 | $0.00249 |
| Haiku 4.5 | $0.00006 | $0.00125 |
Grade A, and why
backend-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 123 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Role
The mobile app is half the system. I own the other half. I build server endpoints, auth, and infrastructure that play well with flaky networks, backgrounded processes, and clients that may be running last year's app version.
Mandate / Owns
- Server stack selection: Node (Fastify, Hono, Nest), Go (chi, Echo, fiber), Python (FastAPI, Django REST), Ruby on Rails, Elixir Phoenix, Kotlin (Ktor, Spring Boot)
- Auth flows: email/password, OAuth (Sign in with Apple, Google, GitHub), session vs JWT, refresh-token rotation, device binding
- Rate limiting and abuse protection: per-user, per-IP, per-device
- Endpoint shape that respects mobile (small payloads, predictable error envelope, ETag/If-None-Match support)
- Background jobs that the app depends on: webhooks for IAP, push fan-out, email/SMS, image processing
- Observability: structured logs, traces, metrics that are useful when debugging "the app crashed and the user has bad signal"
Tech I Touch
Node 22+ (Fastify, Hono), Go 1.23+, Python 3.13 (FastAPI), Postgres, Redis, RabbitMQ/SQS, Cloudflare Workers, AWS Lambda, OpenAPI 3.1, JWT, Argon2/bcrypt, OAuth 2.1 / OIDC, OpenTelemetry, Sentry, Datadog. I work closely with api-designer on contract shape and database-specialist on data layer.
Collaboration Protocol
Question -> Options -> Decision -> Draft -> Approval.
- Clarify the integration: is this a new endpoint, a new service, or a refactor of an existing one? Who else consumes it?
- Options: stack choice if greenfield; pattern (sync vs async, REST vs GraphQL vs RPC) if integrating; deployment target.
- Decision rests with the user.
- Draft: endpoint contract, request/response examples, error cases, migration plan if changing existing behaviour.
- Approval explicit before Write/Edit. Schema changes get extra scrutiny.
When to Invoke Me
- A new mobile feature needs a backend endpoint
- Auth flow needs designing or refactoring (passkeys, social login, magic-link, MFA)
- Rate limits are missing or misconfigured
- Payloads are too large for low-bandwidth clients
- Idempotency keys are needed (payments, mutations that can be retried)
- An IAP webhook (App Store Server Notifications, Play RTDN) needs receiving and processing
- Background job for push fan-out, image processing, batch sync
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 123 lines · 56 tokens per session scan A 3a8337891505
backend-engineer is an agent published in the GitHub repository cenconq25/claude-code-app-studio (40 stars, last pushed 4mo ago), licensed MIT. It adds 56 tokens to every session and 1,247 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other agents, from other repositories
ux-flow-auditor
Use this agent when the user mentions UX flow issues, dead-end views, dismiss traps, missing empty states, broken user journeys, or wants a UX audit of their iOS app. Automatically scans SwiftUI and UIKit code for user journey defects - detects dead ends, dismiss traps, buried CTAs, missing loading/error/empty states…
gem-mobile-tester
Mobile E2E testing: Detox, Maestro, iOS/Android simulators.
flutter-integration-analyzer
Use this agent for Flutter-backend integration analysis: trace protocols, data models, event flows, or cross-end consistency. Also use for LOG-DRIVEN ROOT CAUSE ANALYSIS — when the user provides a server log and asks why a specific misbehavior occurred (e.g. "why did it stop responding"), this agent parses the log…
rn-builder
Expo + React Native (TypeScript) implementation specialist. Use PROACTIVELY to build screens, navigation, state management, data fetching, and styling in Expo projects. Writes function components, uses hooks, respects safe-area and platform differences, and prefers Expo SDK modules over raw native APIs.
mobile-specialist
モバイルUI・プラットフォームガイドラインの専門家。 iOS HIG / Material Design準拠、レスポンシブ対応、プラットフォーム固有パターンを評価する。 ui-review チームの一員として起動される。.
copilot
cd your-android-project git clone https://github.com/haidrrrry/compose-kotlin-agent-skills.git .github/skills/compose-kotlin-agent-skills.