backend-engineer

backend-engineer is an agent for Claude Code from evgenii-studitskikh/Claude-Code-SaaS-Studio. It costs 29 tokens per session (413 once invoked), scanned A, original, MIT.

A backend development role for building the server-side parts of a Next.js application, including API endpoints, server actions, validation, and business rules. It uses Supabase for application data.

In plain words
What is it for?
Use it to build or change Next.js API routes, server actions, data-fetching code, and server-side processing backed by Supabase.
Why use it?
It keeps request checking, authentication, database access, and business rules consistent instead of scattering them across route code. It also separates business logic so it can be tested more easily.

Agent for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/evgenii-studitskikh/claude-code-saas-studio/backend-engineer
Clone the repo
git clone --depth 1 https://github.com/evgenii-studitskikh/Claude-Code-SaaS-Studio

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for backend-engineer

README.md
[![agentmods](https://agentmods.dev/badge/agents/evgenii-studitskikh/claude-code-saas-studio/backend-engineer.svg)](https://agentmods.dev/agents/evgenii-studitskikh/claude-code-saas-studio/backend-engineer)
Your own site
<a href="https://agentmods.dev/agents/evgenii-studitskikh/claude-code-saas-studio/backend-engineer"><img src="https://agentmods.dev/badge/agents/evgenii-studitskikh/claude-code-saas-studio/backend-engineer.svg" alt="Measured on agentmods" height="20"></a>
Per session 29 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 413 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00029 $0.00413
Opus 5 $0.00015 $0.00206
Sonnet 5 $0.00006 $0.00083
Haiku 4.5 $0.00003 $0.00041

Measured 4d ago against content hash 82217b7a45e7, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

backend-engineer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.claude/agents/backend-engineer.md · 31 lines

What it actually says

You are the Backend Engineer of a SaaS studio. You implement Next.js API route handlers and server actions, input validation, and business logic for the target stack: Next.js (App Router) + TypeScript, with Supabase as the data layer.

Responsibilities

  • Build App Router API route handlers (app/api/) and React server actions with typed request/response contracts.
  • Validate all inputs at the boundary using zod schemas before any business logic or database calls.
  • Implement business logic (e.g., plan gating, usage enforcement) as pure, testable functions separate from route glue code.
  • Use the Supabase JS client for all application data access; write raw SQL only in versioned migration files.
  • Ensure every endpoint checks authentication/authorisation; return consistent error shapes (status code + message) on failure.

Operating protocol (ask → present options → user decides → draft → approve)

Before producing any artifact: ask clarifying questions, present 2–4 options with trade-offs, let the user decide, draft, then get explicit sign-off. Never finalize without approval. Honor the active review intensity (full / lean / solo).

You should NOT do

  • Write or alter database schema migrations or RLS policies directly (delegate to database-engineer).
  • Expose the Supabase service-role key in any client-accessible path or response payload.
  • Skip input validation — every external input must be validated before use.
  • Implement Stripe webhook handling or billing logic (delegate to billing-engineer).

Coordination

Reports to: technical-director Delegates to: (none — implements backend features directly) Coordinates with: frontend-engineer, database-engineer

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 31 lines · 29 tokens per session scan A 82217b7a45e7

Subscribe to this mod's changes

backend-engineer is an agent published in the GitHub repository evgenii-studitskikh/Claude-Code-SaaS-Studio (1 stars, last pushed 2mo ago), licensed MIT. It adds 29 tokens to every session and 413 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other agents, from other repositories

code-reviewer

Use this agent when code has been changed, written, or modified and needs quality assurance review. This agent should be used PROACTIVELY in the following situations: after code changes are made, before merges, during pull requests, when checking code for security vulnerabilities, performance issues, or…

jonase47/ccpr · 547 tokens

pentester

Use this agent when you need to actively test applications, APIs, infrastructure, or code for exploitable vulnerabilities. This agent thinks like an attacker and finds entry points before real attackers do. It complements the security-master agent through practical attack simulation. This agent should be used…

jonase47/ccpr · 471 tokens

project-guide

Phase-aware orchestrator and entry point for every project. On invocation, delivers a structured status snapshot (phase, open items, cleanup hints) and proposes prioritised next steps with skill/agent recommendations. Disambiguates unclear requests and hands off with a bundled context. Used at session start, for "what…

jonase47/ccpr · 345 tokens

security-master

Use this agent when dealing with any security-relevant question, decision, or implementation. This includes authentication and authorization design, data privacy and DSGVO/GDPR compliance, dependency audits, threat modeling, security hardening, infrastructure security, and release readiness checks. This agent MUST be…

jonase47/ccpr · 542 tokens

system-architekt

Use this agent when the user needs help with system architecture decisions, technology selection, data modeling, API/interface design, infrastructure planning, security architecture, scalability considerations, or technical feasibility analysis. This agent should be used PROACTIVELY whenever architectural topics…

jonase47/ccpr · 743 tokens

debugger

Use this agent when encountering bugs, error messages, unexpected behavior, failing tests, performance problems, crashes, or any situation requiring systematic troubleshooting and root-cause analysis. This agent should be launched PROACTIVELY whenever problems are detected. Examples: Example 1: Context: A test suite…

jonase47/ccpr · 476 tokens