{"data":{"skill":{"slug":"amirtaherkhani-nestjs-architecture-principles","name":"nestjs-architecture-principles","icon":"📦","repo":"https://github.com/amirtaherkhani/nestjs-skills/tree/b82cdf0312e1c1bcaf871bb67473e91b2a1befad/skills/nestjs-architecture-principles","status":"approved","author":"amirtaherkhani","authorVersion":"1.1.2","skillstoreRevision":1},"audit":{"id":"bedf68a2-ad9d-477e-95cb-949916a6aafe","skill_id":"1f5937ea-94d2-4bda-8ef8-0c6f0a7c2d5a","version":1,"content_hash":"v3:c97a1862d1bc82763903ee068cd15acab35d638c:88d31a9a58c638547bb814928d8cb46f62c0767990242ada5fe94efad4364d94:4af59f36093980615450618f5344063c94b2b93767c91925ef306592672ce137:736b696c6c732f616d697274616865726b68616e692f6e6573746a732d6172636869746563747572652d7072696e6369706c6573:0153305673704f3ac38bcc08044c6cd0","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 19 static findings are false positives involving architecture guidance, Markdown formatting, or illustrative configuration access. The payment example passes configuration to an adapter without logging or exporting credentials. No evidence found of malicious intent, prompt injection, reconnaissance, or shell execution in the reviewed files.","remediation":[],"risk_factor_evidence":[{"factor":"env_access","evidence":[{"file":"references/module-boundaries.md","line_end":76,"line_start":76},{"file":"references/module-boundaries.md","line_end":77,"line_start":77}]},{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":73,"line_start":73}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":10,"total_lines":1031,"audit_model":"codex","audited_at":"2026-10-04T20:29:35.104+00:00","created_at":"2026-10-05T12:54:13.135459+00:00","static_findings":[{"id":"blocker:references/database-orm.md:22:system-reconnaissance","file":"references/database-orm.md","pattern":"System reconnaissance","snippet":"3. Avoid automatic schema synchronization in production.","category":"blocker","line_end":22,"severity":"low","line_start":22},{"id":"blocker:references/database-orm.md:33:system-reconnaissance","file":"references/database-orm.md","pattern":"System reconnaissance","snippet":"- Keep transactions short and avoid remote HTTP, broker, email, or file calls while locks are held.","category":"blocker","line_end":33,"severity":"low","line_start":33},{"id":"blocker:references/dependency-injection.md:90:system-reconnaissance","file":"references/dependency-injection.md","pattern":"System reconnaissance","snippet":"## Avoid service location","category":"blocker","line_end":90,"severity":"low","line_start":90},{"id":"blocker:references/dependency-injection.md:92:system-reconnaissance","file":"references/dependency-injection.md","pattern":"System reconnaissance","snippet":"Constructor injection makes dependencies visible and testable. `ModuleRef.get()` or runtime discover","category":"blocker","line_end":92,"severity":"low","line_start":92},{"id":"blocker:references/engineering-principles.md:52:system-reconnaissance","file":"references/engineering-principles.md","pattern":"System reconnaissance","snippet":"A module should expose what consumers need and hide schema, caching, retry, and mapping decisions. A","category":"blocker","line_end":52,"severity":"low","line_start":52},{"id":"blocker:references/engineering-principles.md:58:system-reconnaissance","file":"references/engineering-principles.md","pattern":"System reconnaissance","snippet":"Avoid navigation chains that make one feature understand another feature's object graph:","category":"blocker","line_end":58,"severity":"low","line_start":58},{"id":"blocker:references/engineering-principles.md:72:system-reconnaissance","file":"references/engineering-principles.md","pattern":"System reconnaissance","snippet":"Place decisions with the object or policy that owns the invariant. Application services may still qu","category":"blocker","line_end":72,"severity":"low","line_start":72},{"id":"blocker:references/engineering-principles.md:80:system-reconnaissance","file":"references/engineering-principles.md","pattern":"System reconnaissance","snippet":"Reject invalid configuration at startup. At runtime, distinguish retryable, non-retryable, partial, ","category":"blocker","line_end":80,"severity":"low","line_start":80},{"id":"blocker:references/microservices.md:30:system-reconnaissance","file":"references/microservices.md","pattern":"System reconnaissance","snippet":"Each service owns its write model. Avoid shared-table writes and cross-service joins that make indep","category":"blocker","line_end":30,"severity":"low","line_start":30},{"id":"env_access:references/module-boundaries.md:76:configuration-library","file":"references/module-boundaries.md","pattern":"Configuration library","snippet":"config.getOrThrow('PAYMENTS_MODE') === 'live'","category":"env_access","line_end":76,"severity":"low","line_start":76},{"id":"env_access:references/module-boundaries.md:77:configuration-library","file":"references/module-boundaries.md","pattern":"Configuration library","snippet":"? new StripePaymentGateway(config.getOrThrow('STRIPE_KEY'))","category":"env_access","line_end":77,"severity":"low","line_start":77},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-oop-design-patterns`: object responsibilities, invariants, and patterns.","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-features-performance`: lifecycle, API/security, testing, runtime, and performance.","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-professional-software-engineering`: implementation and verification.","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-code-audit`: read-only quality evidence and deduplicated reporting.","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-feature-audit`: branch-specific roadmap gate and feature reporting.","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-git-commit-pr-message`: authorized Git publication and CI follow-up.","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. Read `package.json`, `nest-cli.json`, TypeScript configuration, bootstrap files, and the relevant","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"7. **Cycles are design feedback.** Treat `forwardRef()` as a last-resort compatibility tool, not the","category":"external_commands","line_end":73,"severity":"medium","line_start":73}],"finding_verdicts":[{"id":"blocker:references/database-orm.md:22:system-reconnaissance","reason":"The line discourages automatic production schema synchronization within migration safety guidance. It contains no host discovery or reconnaissance operation.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/database-orm.md:33:system-reconnaissance","reason":"The line advises avoiding remote calls while transaction locks are held. It neither performs those calls nor requests system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/dependency-injection.md:90:system-reconnaissance","reason":"The heading introduces guidance against the service locator pattern. Service location here concerns dependency injection, not discovering host services.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/dependency-injection.md:92:system-reconnaissance","reason":"The paragraph explains constructor injection and limited uses of ModuleRef.get() in framework extensions. Runtime discovery refers to application providers, not host reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/engineering-principles.md:52:system-reconnaissance","reason":"The paragraph recommends hiding persistence and vendor implementation details behind module APIs. It does not inspect the host or enumerate system resources.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/engineering-principles.md:58:system-reconnaissance","reason":"The line introduces a Law of Demeter example about object navigation chains. The surrounding TypeScript example concerns business objects, not system discovery.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/engineering-principles.md:72:system-reconnaissance","reason":"The paragraph assigns business decisions to invariant owners and allows application orchestration. Querying state here means business state, not collecting host information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/engineering-principles.md:80:system-reconnaissance","reason":"The paragraph recommends startup validation and safe failure handling. It explicitly forbids fallbacks that bypass authorization, billing, or data integrity.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/microservices.md:30:system-reconnaissance","reason":"The line defines service data ownership and discourages shared-table writes and cross-service joins. It contains no system discovery instruction.","verdict":"false_positive","confidence":0.99},{"id":"env_access:references/module-boundaries.md:76:configuration-library","reason":"The fenced TypeScript example reads PAYMENTS_MODE to select an adapter at the composition root. This is illustrative application configuration, not secret harvesting.","verdict":"false_positive","confidence":0.98},{"id":"env_access:references/module-boundaries.md:77:configuration-library","reason":"The example passes STRIPE_KEY to the intended payment adapter constructor. No logging, unrelated destination, or instruction to extract the auditor's credentials appears.","verdict":"false_positive","confidence":0.98},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"Backticks format a related skill name in a Markdown list. The line describes object-design ownership and contains no executable shell command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"Backticks format a related skill name in Markdown. The entry describes runtime and performance responsibilities, not shell execution.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The backtick-delimited text is a skill identifier, not a command substitution. The entry only identifies implementation and verification responsibilities.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The line names a related auditing skill using Markdown code formatting. It describes read-only reporting and does not invoke an external command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The backticks delimit a related feature-audit skill name in Markdown. The line defines reporting ownership without executing any command.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The line names a Git publication skill using Markdown formatting. It describes authorized publication ownership without issuing commands or granting publication authorization.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"Backticks format repository filenames in a read-only inspection step. No shell syntax or executable command is present.","verdict":"false_positive","confidence":1},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"Backticks format the NestJS forwardRef() API name. The guidance discourages routine use of circular-dependency workarounds and contains no shell execution.","verdict":"false_positive","confidence":1}],"semantic_findings":[],"subject_marketplace_commit_sha":"c97a1862d1bc82763903ee068cd15acab35d638c","subject_content_hash":"88d31a9a58c638547bb814928d8cb46f62c0767990242ada5fe94efad4364d94","subject_tree_hash":"4af59f36093980615450618f5344063c94b2b93767c91925ef306592672ce137","subject_plugin_path":"skills/amirtaherkhani/nestjs-architecture-principles","audit_payload_hash":"0153305673704f3ac38bcc08044c6cd0","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"c97a1862d1bc82763903ee068cd15acab35d638c","contentHash":"88d31a9a58c638547bb814928d8cb46f62c0767990242ada5fe94efad4364d94","treeHash":"4af59f36093980615450618f5344063c94b2b93767c91925ef306592672ce137","pluginPath":"skills/amirtaherkhani/nestjs-architecture-principles","auditPayloadHash":"0153305673704f3ac38bcc08044c6cd0"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/amirtaherkhani-nestjs-architecture-principles/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}