# Cosmosmith Backend Engineer

> Implement backend task slices from a Cosmosmith task ledger. Use when task.md assigns API, persistence, domain logic, permissions, migrations, integrations, observability, or server-side tests; use current official docs for frameworks, databases, and services when needed.

- **Type:** Skill
- **Install:** `agentstack add skill-devnomad-byte-cosmosmith-cosmosmith-backend-engineer`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [devnomad-byte](https://agentstack.voostack.com/s/devnomad-byte)
- **Installs:** 0
- **Category:** [Cloud & Infrastructure](https://agentstack.voostack.com/c/cloud-infrastructure)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [devnomad-byte](https://github.com/devnomad-byte)
- **Source:** https://github.com/devnomad-byte/cosmosmith/tree/main/plugins/cosmosmith/skills/cosmosmith-backend-engineer
- **Website:** https://www.npmjs.com/package/cosmosmith

## Install

```sh
agentstack add skill-devnomad-byte-cosmosmith-cosmosmith-backend-engineer
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Cosmosmith Backend Engineer

## Purpose

Claim and implement backend tasks with explicit contracts and evidence.

## Workflow

1. Read `task.md`, `design.md`, architecture artifacts, and relevant backend code.
2. Claim one `queued` backend task by setting it to `claimed`.
3. Use web research for current framework, database, API, cloud, or security docs when needed.
4. Implement domain behavior behind clear interfaces.
5. Validate inputs, permissions, data consistency, error paths, logging, and observability.
6. Run available unit, integration, migration, and contract checks.
7. Update `task.md` with evidence and status.

## Standards

- Prefer explicit schemas and migrations.
- Use Alibaba/P3C-style backend discipline when Java or similar enterprise stacks are present.
- Use OWASP-style security review for web/API surfaces.
- Keep secrets out of code and docs.

## Completion

Stop when the backend task is implemented, verified, and recorded in `task.md`.

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [devnomad-byte](https://github.com/devnomad-byte)
- **Source:** [devnomad-byte/cosmosmith](https://github.com/devnomad-byte/cosmosmith)
- **License:** MIT
- **Homepage:** https://www.npmjs.com/package/cosmosmith

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-devnomad-byte-cosmosmith-cosmosmith-backend-engineer
- Seller: https://agentstack.voostack.com/s/devnomad-byte
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
