Backend / API starter
Services, REST/GraphQL APIs, databases
Install
Run in your project root. Existing files are never overwritten (unzip -n / [ -e … ] skip them). Review AGENTS.md and fill in the <placeholders>.
$ curl -fsSL https://agentrigs.dev/starters/agentrigs-backend-api.zip -o agentrigs-starter.zip && unzip -n agentrigs-starter.zip && chmod +x .claude/hooks/guard.sh && rm agentrigs-starter.zip $ npx degit affaan-m/ECC/.agents/skills/api-design .claude/skills/api-design $ npx degit obra/superpowers/skills/test-driven-development .claude/skills/test-driven-development $ npx degit obra/superpowers/skills/systematic-debugging .claude/skills/systematic-debugging $ npx degit affaan-m/ECC/.kiro/skills/database-migrations .claude/skills/database-migrations
Or download agentrigs-backend-api.zip (6 files). Skills are fetched from their source repos with npx degit.
mkdir -p .claude/hooks
[ -e AGENTS.md ] && echo "skip AGENTS.md (exists)" || cat > AGENTS.md <<'AGENTRIGS_EOF'
# Service
<one paragraph: what the service does, its main entities, where it runs>
## Commands
- Run: `make dev` · Test: `make test` · Lint: `make lint` · Migrations: `make migrate` (never against production)
## Conventions
- Validate input at the edge; return typed errors with stable error codes.
- Every endpoint change ships with a test (happy path + one failure).
- Database: forward-only migrations, reversible where possible; never edit an applied migration.
- No secrets in code or logs; config comes from environment variables.
- Log structured JSON with a request id; no PII in logs.
## Checks before done
`make lint && make test`; for schema changes, show the migration and its rollback.
## Workflow
1. Restate the task in one line and list the files you expect to touch.
2. Make the smallest change that works; keep diffs reviewable.
3. Run the checks below before saying you're done, and show the output.
4. If something is ambiguous, ask one precise question instead of guessing.
## Safety
- Never read or print secrets (.env, keys, ~/.ssh). Ask for values instead.
- No destructive commands (rm -rf, force-push, reset --hard) without explicit approval; the guard hook blocks them anyway.
- Don't add dependencies, services or paid APIs without asking.
AGENTRIGS_EOF
[ -e CLAUDE.md ] && echo "skip CLAUDE.md (exists)" || cat > CLAUDE.md <<'AGENTRIGS_EOF'
@AGENTS.md
# Claude Code notes
- Use plan mode for multi-file changes. Prefer the installed skills over ad-hoc procedures.
AGENTRIGS_EOF
[ -e .claude/settings.json ] && echo "skip .claude/settings.json (exists)" || cat > .claude/settings.json <<'AGENTRIGS_EOF'
{
"permissions": {
"deny": [
"Bash(rm -rf:*)",
"Bash(rm -fr:*)",
"Bash(sudo:*)",
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(git reset --hard:*)",
"Bash(git clean -fd:*)",
"Read(./.env)",
"Read(./.env.*)",
"Read(./**/.env)",
"Read(./secrets/**)",
"Read(~/.ssh/**)",
"Read(~/.aws/**)",
"Read(./**/*.pem)"
],
"ask": [
"Bash(git push:*)",
"Bash(npm publish:*)",
"Bash(docker:*)",
"Bash(curl:*)"
],
"defaultMode": "default"
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash|Read|Edit|Write",
"hooks": [
{
"type": "command",
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/guard.sh"
}
]
}
]
}
}
AGENTRIGS_EOF
[ -e .claude/hooks/guard.sh ] && echo "skip .claude/hooks/guard.sh (exists)" || cat > .claude/hooks/guard.sh <<'AGENTRIGS_EOF'
#!/usr/bin/env bash
# .claude/hooks/guard.sh: PreToolUse guard. Exit code 2 blocks the tool call and shows the reason to the model.
# Requires jq. Make executable: chmod +x .claude/hooks/guard.sh
input=$(cat)
tool=$(printf '%s' "$input" | jq -r '.tool_name // empty')
cmd=$(printf '%s' "$input" | jq -r '.tool_input.command // empty')
path=$(printf '%s' "$input" | jq -r '.tool_input.file_path // .tool_input.path // empty')
if [ "$tool" = "Bash" ]; then
if printf '%s' "$cmd" | grep -Eq '(^|[;&| ])(sudo|mkfs|dd if=)|rm -[a-zA-Z]*r[a-zA-Z]*f|rm -[a-zA-Z]*f[a-zA-Z]*r|git push .*(--force|-f( |$))|git reset --hard|git clean -[a-z]*f|curl[^|]*\|[[:space:]]*(ba)?sh|chmod 777'; then
echo "Blocked by guard.sh: destructive command ($cmd). Ask the user to run it manually." >&2; exit 2
fi
fi
if printf '%s %s' "$path" "$cmd" | grep -Eq '(^|/|[[:space:]])\.env($|\.|[[:space:]])|id_rsa|\.pem($|[[:space:]])|\.ssh/|\.aws/credentials'; then
echo "Blocked by guard.sh: secrets file ($path$cmd)." >&2; exit 2
fi
exit 0
AGENTRIGS_EOF
[ -e .mcp.json ] && echo "skip .mcp.json (exists)" || cat > .mcp.json <<'AGENTRIGS_EOF'
{
"mcpServers": {
"context7": {
"type": "http",
"url": "https://mcp.context7.com/mcp"
}
}
}
AGENTRIGS_EOF
[ -e AGENTRIGS-STARTER.md ] && echo "skip AGENTRIGS-STARTER.md (exists)" || cat > AGENTRIGS-STARTER.md <<'AGENTRIGS_EOF'
# AgentRigs starter: Backend / API
Generated by https://agentrigs.dev/starters/backend-api from real, well-guarded public rigs:
- https://github.com/RyanAlberts/best-of-Agent-Harnesses
- https://github.com/hanygheit/ai-agent-on-call
- https://github.com/msiShariful/claude-code-studio
## Install
1. Unzip into your repo root (`unzip -n` won't overwrite existing files).
2. `chmod +x .claude/hooks/guard.sh` (needs `jq`).
3. Fill in the <placeholders> in AGENTS.md.
4. Install the recommended skills (third-party code, so review first):
```bash
npx degit affaan-m/ECC/.agents/skills/api-design .claude/skills/api-design
npx degit obra/superpowers/skills/test-driven-development .claude/skills/test-driven-development
npx degit obra/superpowers/skills/systematic-debugging .claude/skills/systematic-debugging
npx degit affaan-m/ECC/.kiro/skills/database-migrations .claude/skills/database-migrations
```
Optional MCP servers (each adds context tax every turn):
```bash
claude mcp add --transport http sentry https://mcp.sentry.dev/mcp
```
Codex / Cursor / other harnesses read AGENTS.md directly; Claude Code reads CLAUDE.md, which imports AGENTS.md.
AGENTRIGS_EOF
chmod +x .claude/hooks/guard.sh
npx degit affaan-m/ECC/.agents/skills/api-design .claude/skills/api-design # skill: api-design
npx degit obra/superpowers/skills/test-driven-development .claude/skills/test-driven-development # skill: test-driven-development
npx degit obra/superpowers/skills/systematic-debugging .claude/skills/systematic-debugging # skill: systematic-debugging
npx degit affaan-m/ECC/.kiro/skills/database-migrations .claude/skills/database-migrations # skill: database-migrations Optional MCP servers (add only if you use them; each adds tool schemas to every turn):
$ claude mcp add --transport http sentry https://mcp.sentry.dev/mcp Context tax
Claude Code pays for CLAUDE.md plus the imported AGENTS.md (~349 tok of instructions); Codex reads AGENTS.md alone (~318 tok). Index median: 2.3k tok. How we measure.
Guardrails
Files
# Service <one paragraph: what the service does, its main entities, where it runs> ## Commands - Run: `make dev` · Test: `make test` · Lint: `make lint` · Migrations: `make migrate` (never against production) ## Conventions - Validate input at the edge; return typed errors with stable error codes. - Every endpoint change ships with a test (happy path + one failure). - Database: forward-only migrations, reversible where possible; never edit an applied migration. - No secrets in code or logs; config comes from environment variables. - Log structured JSON with a request id; no PII in logs. ## Checks before done `make lint && make test`; for schema changes, show the migration and its rollback. ## Workflow 1. Restate the task in one line and list the files you expect to touch. 2. Make the smallest change that works; keep diffs reviewable. 3. Run the checks below before saying you're done, and show the output. 4. If something is ambiguous, ask one precise question instead of guessing. ## Safety - Never read or print secrets (.env, keys, ~/.ssh). Ask for values instead. - No destructive commands (rm -rf, force-push, reset --hard) without explicit approval; the guard hook blocks them anyway. - Don't add dependencies, services or paid APIs without asking.
@AGENTS.md # Claude Code notes - Use plan mode for multi-file changes. Prefer the installed skills over ad-hoc procedures.
{
"permissions": {
"deny": [
"Bash(rm -rf:*)",
"Bash(rm -fr:*)",
"Bash(sudo:*)",
"Bash(git push --force:*)",
"Bash(git push -f:*)",
"Bash(git reset --hard:*)",
"Bash(git clean -fd:*)",
"Read(./.env)",
"Read(./.env.*)",
"Read(./**/.env)",
"Read(./secrets/**)",
"Read(~/.ssh/**)",
"Read(~/.aws/**)",
"Read(./**/*.pem)"
],
"ask": [
"Bash(git push:*)",
"Bash(npm publish:*)",
"Bash(docker:*)",
"Bash(curl:*)"
],
"defaultMode": "default"
},
"hooks": {
"PreToolUse": [
{
"matcher": "Bash|Read|Edit|Write",
"hooks": [
{
"type": "command",
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/guard.sh"
}
]
}
]
}
}
#!/usr/bin/env bash
# .claude/hooks/guard.sh: PreToolUse guard. Exit code 2 blocks the tool call and shows the reason to the model.
# Requires jq. Make executable: chmod +x .claude/hooks/guard.sh
input=$(cat)
tool=$(printf '%s' "$input" | jq -r '.tool_name // empty')
cmd=$(printf '%s' "$input" | jq -r '.tool_input.command // empty')
path=$(printf '%s' "$input" | jq -r '.tool_input.file_path // .tool_input.path // empty')
if [ "$tool" = "Bash" ]; then
if printf '%s' "$cmd" | grep -Eq '(^|[;&| ])(sudo|mkfs|dd if=)|rm -[a-zA-Z]*r[a-zA-Z]*f|rm -[a-zA-Z]*f[a-zA-Z]*r|git push .*(--force|-f( |$))|git reset --hard|git clean -[a-z]*f|curl[^|]*\|[[:space:]]*(ba)?sh|chmod 777'; then
echo "Blocked by guard.sh: destructive command ($cmd). Ask the user to run it manually." >&2; exit 2
fi
fi
if printf '%s %s' "$path" "$cmd" | grep -Eq '(^|/|[[:space:]])\.env($|\.|[[:space:]])|id_rsa|\.pem($|[[:space:]])|\.ssh/|\.aws/credentials'; then
echo "Blocked by guard.sh: secrets file ($path$cmd)." >&2; exit 2
fi
exit 0
{
"mcpServers": {
"context7": {
"type": "http",
"url": "https://mcp.context7.com/mcp"
}
}
}
# AgentRigs starter: Backend / API Generated by https://agentrigs.dev/starters/backend-api from real, well-guarded public rigs: - https://github.com/RyanAlberts/best-of-Agent-Harnesses - https://github.com/hanygheit/ai-agent-on-call - https://github.com/msiShariful/claude-code-studio ## Install 1. Unzip into your repo root (`unzip -n` won't overwrite existing files). 2. `chmod +x .claude/hooks/guard.sh` (needs `jq`). 3. Fill in the <placeholders> in AGENTS.md. 4. Install the recommended skills (third-party code, so review first): ```bash npx degit affaan-m/ECC/.agents/skills/api-design .claude/skills/api-design npx degit obra/superpowers/skills/test-driven-development .claude/skills/test-driven-development npx degit obra/superpowers/skills/systematic-debugging .claude/skills/systematic-debugging npx degit affaan-m/ECC/.kiro/skills/database-migrations .claude/skills/database-migrations ``` Optional MCP servers (each adds context tax every turn): ```bash claude mcp add --transport http sentry https://mcp.sentry.dev/mcp ``` Codex / Cursor / other harnesses read AGENTS.md directly; Claude Code reads CLAUDE.md, which imports AGENTS.md.
Recommended skills
REST API design patterns including resource naming, status codes, pagination, filtering, error responses, versioning, and rate limiting for production APIs.
Use when implementing any feature or bugfix, before writing implementation code
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes
Database migration best practices for schema changes, data migrations, rollbacks, and zero-downtime deployments across PostgreSQL, MySQL, and common ORMs (Prisma, Drizzle, Kysely, Django, TypeORM, gol
Built from these rigs
The rules, permissions and hook pattern were distilled from well-guarded public rigs that match this use case (guardrail score ≥ 3, lean context):