Back to Skills

nestjs-code-review

Provides comprehensive code review capability for NestJS applications, analyzing controllers, services, modules, guards, interceptors, pipes, dependency injection, and database integration patterns. Use when reviewing NestJS code changes, before merging pull requests, after implementing new features, or for architecture validation. Triggers on "review NestJS code", "NestJS code review", "check my NestJS controller/service".

317stars37forksUpdated 8/4/2026

Security Assessment

Safe(95/100)
Security Score95/100

About nestjs-code-review

nestjs-code-review provides a structured, severity-classified code review capability for NestJS applications. It addresses the problem that NestJS codebases accumulate architectural drift — fat controllers, god services, broken dependency injection, circular dependencies, monolithic modules — that is hard to catch consistently in manual review. The skill gives an agent a repeatable checklist covering controllers, services, modules, guards, interceptors, pipes, dependency injection, and database integration patterns (TypeORM, Prisma, Drizzle), and it can delegate deeper analysis to a nestjs-code-review-expert agent.

The workflow is prescriptive: identify the review scope using glob and grep, analyze module structure and boundaries, validate constructor-based dependency injection and provider scoping, evaluate controllers for thinness and proper DTO/validation usage, assess services for single-responsibility and error handling, check security (guards, class-validator input validation, protection against injection/XSS/CSRF), review testing strategy, and produce a report of Critical/Warning/Suggestion findings. A required validation checkpoint forces each Critical and Warning finding to carry reproducible evidence (file path, line numbers, snippet) and a concrete fix, downgrading subjective style preferences. Bundled reference files document anti-patterns, a checklist, and recommended patterns with good/bad TypeScript examples.

It targets NestJS/TypeScript backend developers and teams who want consistent architecture validation before merging pull requests, after implementing features, or during refactoring. The allowed tools are read-oriented (Read, Edit, Grep, Glob, Bash) and the skill is used for analysis and reporting rather than executing risky operations.

FAQ

What does the review cover?

Module structure and boundaries, dependency injection and provider scoping, controller thinness and DTO/validation usage, service responsibilities and error handling, security (guards, class-validator, injection/XSS/CSRF), and test coverage — with findings classified as Critical, Warning, or Suggestion.

How does it avoid noisy or subjective findings?

It includes a required validation checkpoint: every Critical and Warning finding must have reproducible evidence (file path, line numbers, exact snippet) and a concrete actionable fix. Style preferences and findings without remediation are removed or downgraded.

Which database integrations does it understand?

The skill references TypeORM, Prisma, and Drizzle when reviewing database integration patterns.

How is the skill triggered?

Phrases like 'review NestJS code', 'NestJS code review', or 'check my NestJS controller/service', and contexts such as before merging PRs or after implementing new features.

Does it modify my code automatically?

It is primarily a review skill that produces a structured report with recommendations and code examples; its allowed tools include Read, Edit, Grep, Glob, and Bash, but its purpose is analysis and reporting rather than sweeping automated changes.

All Files

4 files
references/anti-patterns.md7.2 KB
View
SKILL.md8.9 KB
View
references/checklist.md4.3 KB
View
references/patterns.md6.3 KB
View

Install nestjs-code-review

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill