backend-websocket-patterns

backend-websocket-patterns is a skill for Claude Code, Codex from j4flmao/agent-skills. It costs 132 tokens per session (4,849 once invoked), scanned A, original, MIT.

A guide to designing WebSocket services for ongoing two-way communication between clients and servers. WebSockets keep a connection open so updates can arrive without repeated requests.

In plain words
What is it for?
Use it to specify chat systems, live notifications, broadcasts, Socket.IO services, Server-Sent Events, and other real-time updates.
Why use it?
It helps standardize authentication, message formats, reconnection, rooms, error handling, and scaling across multiple servers.

Skill for Claude CodeCodex

Written for no agent in particular: nothing here depends on one. Also seen: mentions Codex.

Good fit Use it to specify chat systems, live notifications, broadcasts, Socket.IO services, Server-Sent Events, and other real-time updates.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/j4flmao/agent-skills/websocket-patterns
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add j4flmao/agent-skills --skill websocket-patterns
Clone the repo
git clone --depth 1 https://github.com/j4flmao/agent-skills

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for backend-websocket-patterns

README.md
[![agentmods](https://agentmods.dev/badge/skills/j4flmao/agent-skills/websocket-patterns/github.svg)](https://agentmods.dev/skills/j4flmao/agent-skills/websocket-patterns)
Your own site
<a href="https://agentmods.dev/skills/j4flmao/agent-skills/websocket-patterns"><img src="https://agentmods.dev/badge/skills/j4flmao/agent-skills/websocket-patterns/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for backend-websocket-patterns

Your own site · 80×15
<a href="https://agentmods.dev/skills/j4flmao/agent-skills/websocket-patterns"><img src="https://agentmods.dev/badge/skills/j4flmao/agent-skills/websocket-patterns.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 132 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 4,849 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe. Third-party audits
  • NVIDIA SkillSpector pass 7 Sept 2026
How audits are shown
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00132 $0.04849
Opus 5 $0.00066 $0.02424
Sonnet 5 $0.00026 $0.00970
Haiku 4.5 $0.00013 $0.00485

Measured 8d ago against content hash d52fa6e61b58, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-11, from the pricing page.

Security

Grade A, and why

backend-websocket-patterns scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/backend/universal/websocket-patterns/SKILL.md · 563 lines

How it starts

The opening of the file, as written. The whole thing — 563 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Backend WebSocket Patterns

Purpose

Design consistent, production-grade WebSocket services. Every connection must follow the same conventions for handshake, message framing, room management, reconnection, error handling, and cross-node scaling.

Agent Protocol

Trigger

Exact user phrases: "WebSocket", "real-time", "socket.io", "WS connection", "reconnection", "WS rooms", "broadcast", "WS scaling", "WS clustering", "pub/sub over WS", "SSE", "Server-Sent Events", "long polling", "WS handshake", "design a WebSocket server".

Input Context

Before activating, verify:

  • The real-time feature being designed is known.
  • The transport (raw WebSocket / Socket.IO / SSE) is chosen. If not, ask: "Raw WebSocket, Socket.IO, or SSE?"
  • The scaling requirement (single node vs multi-node) is known.
  • The authentication model is known.

Output Artifact

No file output unless the user requests it. Produces WebSocket connection specs and message protocols as text.

Response Format

For each message type:

Event: {event_name}
Direction: {client→server | server→client | bidirectional}
Payload: {schema reference}
Ack: {required/optional/none}

For a full connection spec:

## Connection
Endpoint: {ws/wss}://{host}/{path}
Auth: {mechanism}

## Messages
{list of message types}

## Lifecycle
{connection → auth → subscribe → message → disconnect}

No preamble. No postamble. No explanations. No filler/hedging/transitions. Compress output — why use many token when few do trick.

Completion Criteria

  • Connection lifecycle (handshake, auth, heartbeat, teardown) is documented.
  • Every message type has: event name, direction, payload schema, ack requirement.
  • Reconnection strategy (backoff, max attempts, jitter) is defined.
  • Room/subscription model is defined.
  • Scaling strategy (sticky sessions vs external pub/sub) is documented.
  • Error handling and disconnect scenarios are covered.

Max Response Length

Per message type: 5 lines. Per connection spec: unlimited.

Read the full file on GitHub · 563 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 8d ago First seen · 563 lines · 132 tokens per session scan A d52fa6e61b58

Subscribe to this mod's changes

backend-websocket-patterns is a skill published in the GitHub repository j4flmao/agent-skills (23 stars, last pushed 5d ago), licensed MIT. It adds 132 tokens to every session and 4,849 once invoked, about $0.0007 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

hunt-websocket

Hunt WebSocket vulnerabilities — Cross-Site WebSocket Hijacking (CSWSH), missing/weak Origin validation on the WS handshake, no per-message authentication, message tampering, socket.io namespace/room authorization bypass, and handshake-layer Upgrade smuggling. Use when target has WebSocket endpoints (ws:// or wss://)…

uphiago/recon-skills · 95 tokens

opentelemetry

OpenTelemetry observability patterns: traces, metrics, logs, context propagation, OTLP export, Collector pipelines, and troubleshooting.

bobmatnyc/claude-mpm-skills · 29 tokens

kui-framework

Guide for building web applications with the Kui framework. Use when writing Kui ASGI/WSGI handlers, defining routes, binding parameters, configuring OpenAPI docs, or working with middleware/dependency injection.

abersheeran/kui · 44 tokens

bunjs

Use when building Bun.js/Hono applications, implementing HTTP endpoints, setting up Prisma/SQLite, writing Zod validation, or using Bun's test runner. See bunjs-architecture for layered patterns, bunjs-production for deployment.

MadAppGang/claude-code · 49 tokens

api-reference

OpenAPI/AsyncAPI spec authoring, Swagger UI hosting, endpoint doc patterns, request/response examples, error catalogs, and SDK reference generation for REST and WebSocket APIs.

LuuOW/meridian-mcp · 38 tokens

GraphQL Subscription Testing

Testing GraphQL subscriptions including WebSocket lifecycle, real-time event delivery, authorization on subscriptions, and connection management.

PramodDutta/qaskills · 27 tokens