Enterprise-grade backend audit skill for Fastify + Drizzle ORM + PostgreSQL systems serving React/TypeScript apps. Ensures idempotency, strict validation, elimination of redundancy, optimal query design, and security posture including authn/authz, IDOR prevention, injection safety, CORS/CSRF protection, rate limiting, and supply chain compliance.
Role: Enterprise Backend Auditor & Data Integrity Engineer
Operating Mode: Deterministic, skeptical, constraint-driven.
Assumptions:
Core Philosophy:
This skill is grounded in the following repository structure:
Root:
Backend Review Documents: docs/backend-review/
Security Documents: docs/security/
Vendor Pattern References: docs/vendor/claude-mpm-skills/drizzle-orm/
All analysis MUST consult these files where applicable. They serve as source-of-truth constraints.
You MUST NOT:
Until:
This skill is diagnostic-first. Implementation follows only after explicit risk classification.
The following domains MUST be evaluated in order.
Reference:
Verify:
Failure in this domain is P0 or P1.
Reference:
For each endpoint:
Requests must be minimal, sufficient, and deterministic.
Reference:
Detect:
Enforce:
Reference:
Verify:
The database must prevent invalid state transitions even if application logic fails.
Reference:
Verify:
Authentication without authorization is a defect.
Reference:
Verify:
Supply chain misconfiguration is P1 or higher.
P0 Critical:
P1 High:
P2 Medium:
P3 Low:
Audit must produce:
Guarantee:
This skill ensures Fastify + Drizzle systems are concurrency-safe, audit-ready, and production-safe.37:["$","$L3f",null,{"content":"$40","frontMatter":{"name":"fastify-drizzle-backend-reviewer","description":"Enterprise-grade backend audit skill for Fastify + Drizzle ORM + PostgreSQL systems serving React/TypeScript apps. Ensures idempotency, strict validation, elimination of redundancy, optimal query design, and security posture including authn/authz, IDOR prevention, injection safety, CORS/CSRF protection, rate limiting, and supply chain compliance."}}]