{"data":{"skill":{"slug":"amirtaherkhani-nestjs-oop-design-patterns","name":"nestjs-oop-design-patterns","icon":"📦","repo":"https://github.com/amirtaherkhani/nestjs-skills/tree/b82cdf0312e1c1bcaf871bb67473e91b2a1befad/skills/nestjs-oop-design-patterns","status":"approved","author":"amirtaherkhani","authorVersion":"1.0.2","skillstoreRevision":1},"audit":{"id":"b5eddf4b-6ac6-425a-8fb3-ddf121acdb37","skill_id":"c8b76d47-df14-44d3-a637-391a94513e8e","version":1,"content_hash":"v3:c97a1862d1bc82763903ee068cd15acab35d638c:4489d01ab4098d6908dc095d84621b9281e8574b9ac76d591a70972fbc1a4afe:180bcbf3e6e8054316a23f78f580d8fabf23562d375bfd23713824680839e123:736b696c6c732f616d697274616865726b68616e692f6e6573746a732d6f6f702d64657369676e2d7061747465726e73:2e4aba62ffcd94993d639ea9a7890730","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 25 static findings are false positives involving ordinary design guidance, Markdown identifiers, or headings. Backticks mark inline code, and the reconnaissance matches contain no system enumeration instructions. No evidence found of prompt injection, credential theft, unauthorized execution, or data exfiltration in the reviewed passages and surrounding files.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":26,"line_start":26},{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":28,"line_start":28},{"file":"SKILL.md","line_end":29,"line_start":29},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":78,"line_start":78},{"file":"SKILL.md","line_end":122,"line_start":122},{"file":"SKILL.md","line_end":131,"line_start":131},{"file":"SKILL.md","line_end":140,"line_start":140}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":7,"total_lines":904,"audit_model":"codex","audited_at":"2026-10-04T20:52:37.6+00:00","created_at":"2026-10-05T12:54:56.91277+00:00","static_findings":[{"id":"blocker:references/nestjs-native-patterns.md:21:system-reconnaissance","file":"references/nestjs-native-patterns.md","pattern":"System reconnaissance","snippet":"Use provider tokens for application ports and configuration. Avoid runtime service location unless i","category":"blocker","line_end":21,"severity":"low","line_start":21},{"id":"blocker:references/nestjs-native-patterns.md:51:system-reconnaissance","file":"references/nestjs-native-patterns.md","pattern":"System reconnaissance","snippet":"Avoid catch-and-rethrow filters that add no mapping, context, or observability.","category":"blocker","line_end":51,"severity":"low","line_start":51},{"id":"blocker:references/object-design.md:112:system-reconnaissance","file":"references/object-design.md","pattern":"System reconnaissance","snippet":"Avoid universal mapping frameworks when explicit mapping is short and captures important semantics.","category":"blocker","line_end":112,"severity":"low","line_start":112},{"id":"blocker:references/object-design.md:116:system-reconnaissance","file":"references/object-design.md","pattern":"System reconnaissance","snippet":"Use a factory when valid construction has branching, multiple steps, dependencies, or invariants tha","category":"blocker","line_end":116,"severity":"low","line_start":116},{"id":"blocker:references/object-design.md:121:system-reconnaissance","file":"references/object-design.md","pattern":"System reconnaissance","snippet":"- Avoid vague containers: `Helper`, `Manager`, `CommonService`, `UtilsService`.","category":"blocker","line_end":121,"severity":"low","line_start":121},{"id":"blocker:references/oop-solid.md:34:system-reconnaissance","file":"references/oop-solid.md","pattern":"System reconnaissance","snippet":"Avoid a wrapper that reproduces an entire third-party SDK method for method. It adds a layer but hid","category":"blocker","line_end":34,"severity":"low","line_start":34},{"id":"blocker:references/oop-solid.md:73:system-reconnaissance","file":"references/oop-solid.md","pattern":"System reconnaissance","snippet":"Keep the selection at the composition root or a focused factory. Avoid selecting a strategy from unv","category":"blocker","line_end":73,"severity":"low","line_start":73},{"id":"blocker:references/oop-solid.md:100:system-reconnaissance","file":"references/oop-solid.md","pattern":"System reconnaissance","snippet":"Do not replace a small stable conditional with a class hierarchy solely to avoid modifying a file.","category":"blocker","line_end":100,"severity":"low","line_start":100},{"id":"blocker:references/pattern-catalog.md:29:system-reconnaissance","file":"references/pattern-catalog.md","pattern":"System reconnaissance","snippet":"Keep selection separate from execution. A strategy should not inspect its own type discriminator. Av","category":"blocker","line_end":29,"severity":"low","line_start":29},{"id":"blocker:references/pattern-catalog.md:59:system-reconnaissance","file":"references/pattern-catalog.md","pattern":"System reconnaissance","snippet":"Keep invalid intermediate state inside the builder and return a validated result from `build()`. For","category":"blocker","line_end":59,"severity":"low","line_start":59},{"id":"blocker:references/pattern-catalog.md:107:system-reconnaissance","file":"references/pattern-catalog.md","pattern":"System reconnaissance","snippet":"Avoid events when the producer requires an immediate result to complete its invariant.","category":"blocker","line_end":107,"severity":"low","line_start":107},{"id":"blocker:references/pattern-catalog.md:147:system-reconnaissance","file":"references/pattern-catalog.md","pattern":"System reconnaissance","snippet":"Keep transaction control at the application/infrastructure boundary. Avoid starting transactions in ","category":"blocker","line_end":147,"severity":"low","line_start":147},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-architecture-principles`: module, dependency, data, and transaction boundaries.","category":"external_commands","line_end":26,"severity":"medium","line_start":26},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-features-performance`: lifecycle, API/security, testing, runtime, and performance.","category":"external_commands","line_end":27,"severity":"medium","line_start":27},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-professional-software-engineering`: implementation and verification.","category":"external_commands","line_end":28,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-code-audit`: read-only quality evidence and deduplicated reporting.","category":"external_commands","line_end":29,"severity":"medium","line_start":29},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-feature-audit`: branch-specific roadmap gate and feature reporting.","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- `nestjs-git-commit-pr-message`: authorized Git publication and CI follow-up.","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Does each consumer depend only on the capability it uses? Prefer small application-owned ports over ","category":"external_commands","line_end":78,"severity":"medium","line_start":78},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Instantiate a use case directly when constructor dependencies are simple; use `TestingModule` when","category":"external_commands","line_end":122,"severity":"medium","line_start":122},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"Do not enforce arbitrary limits such as ten-line methods, fifty-line classes, two fields per object,","category":"external_commands","line_end":131,"severity":"medium","line_start":131},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- a generic `BaseService<T>` that erases feature-specific invariants.","category":"external_commands","line_end":140,"severity":"medium","line_start":140},{"id":"blocker:SKILL.md:56:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"- Make invalid states difficult to construct when the domain value justifies the type.","category":"blocker","line_end":56,"severity":"low","line_start":56},{"id":"blocker:SKILL.md:90:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"| Signal | Consider | Avoid when |","category":"blocker","line_end":90,"severity":"low","line_start":90},{"id":"blocker:SKILL.md:129:system-reconnaissance","file":"SKILL.md","pattern":"System reconnaissance","snippet":"## Reject rigid pseudo-rules","category":"blocker","line_end":129,"severity":"low","line_start":129}],"finding_verdicts":[{"id":"blocker:references/nestjs-native-patterns.md:21:system-reconnaissance","reason":"The passage recommends Nest provider tokens and discourages runtime service location. This is dependency injection guidance, not host discovery or system enumeration.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/nestjs-native-patterns.md:51:system-reconnaissance","reason":"The sentence discourages exception filters that merely catch and rethrow errors. Its surrounding section concerns transport error mapping, not reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/object-design.md:112:system-reconnaissance","reason":"The passage favors explicit DTO mapping over unnecessary mapping frameworks. The adjacent TypeScript example maps order input and performs no system inspection.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/object-design.md:116:system-reconnaissance","reason":"The sentence explains when object construction warrants a factory. References to dependencies and invariants concern object design, not operating system reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/object-design.md:121:system-reconnaissance","reason":"Helper, Manager, CommonService, and UtilsService are examples of vague class names to avoid. The passage contains naming advice, not reconnaissance commands.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/oop-solid.md:34:system-reconnaissance","reason":"The sentence discourages wrappers that duplicate an entire SDK without hiding a meaningful decision. This is abstraction guidance without system discovery behavior.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/oop-solid.md:73:system-reconnaissance","reason":"The passage places strategy selection at the composition root and cautions against unvalidated input. This is defensive application design, not system enumeration.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/oop-solid.md:100:system-reconnaissance","reason":"The sentence discourages replacing stable conditionals with unnecessary class hierarchies. It contains no instruction to inspect host state or discover system resources.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/pattern-catalog.md:29:system-reconnaissance","reason":"The strategy section separates algorithm selection from execution and discourages patterns without real variation. Inspecting a type discriminator concerns application objects, not host reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/pattern-catalog.md:59:system-reconnaissance","reason":"The builder section recommends validated construction and parameterized ORM queries. The build() reference is Markdown inline code, and the passage requests no reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/pattern-catalog.md:107:system-reconnaissance","reason":"The sentence discourages asynchronous events when a producer requires an immediate result. It addresses domain consistency, not discovery of system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:references/pattern-catalog.md:147:system-reconnaissance","reason":"The Unit of Work section places transaction control at application boundaries and warns against long network calls inside transactions. This describes application design, not reconnaissance.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"Backticks format the name nestjs-architecture-principles in a list of optional related skills. The line contains no shell command or Ruby executable expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:27:ruby-shell-backtick-execution","reason":"Backticks format the related skill name nestjs-features-performance. The surrounding text describes ownership boundaries and explicitly states these skills are not required dependencies.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The line names nestjs-professional-software-engineering using Markdown inline code. It identifies an optional workflow owner without instructing command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:29:ruby-shell-backtick-execution","reason":"The backticked name nestjs-code-audit labels a related read-only review skill. Neither this line nor its surrounding list contains shell execution syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The backticks mark the optional related skill nestjs-feature-audit as an identifier. The text describes reporting responsibilities, not external command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The line identifies nestjs-git-commit-pr-message as an optional owner of authorized Git publication. It does not invoke Git or authorize publication itself.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:78:ruby-shell-backtick-execution","reason":"CommonService is a backticked class-name example in interface segregation advice. Markdown formatting does not execute the identifier as Ruby or shell code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:122:ruby-shell-backtick-execution","reason":"TestingModule is a Nest testing API name formatted as inline code. The passage explains test selection and contains no external command invocation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:131:ruby-shell-backtick-execution","reason":"The backticked else keyword illustrates an arbitrary style restriction the skill rejects. It is explanatory Markdown, not a shell or Ruby execution expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:140:ruby-shell-backtick-execution","reason":"BaseService<T> is a generic TypeScript class-name example in a list of discouraged abstractions. Its Markdown backticks are not executable command substitution.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:56:system-reconnaissance","reason":"The bullet recommends domain types that prevent invalid states. This is an object invariant rule with no request for system information.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:90:system-reconnaissance","reason":"The flagged text is the header of a Markdown table comparing design patterns. Its columns contain no commands or host discovery instructions.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:129:system-reconnaissance","reason":"Reject rigid pseudo-rules is a section heading about arbitrary code style limits. The surrounding guidance concerns cohesion and readability, not system reconnaissance.","verdict":"false_positive","confidence":0.99}],"semantic_findings":[],"subject_marketplace_commit_sha":"c97a1862d1bc82763903ee068cd15acab35d638c","subject_content_hash":"4489d01ab4098d6908dc095d84621b9281e8574b9ac76d591a70972fbc1a4afe","subject_tree_hash":"180bcbf3e6e8054316a23f78f580d8fabf23562d375bfd23713824680839e123","subject_plugin_path":"skills/amirtaherkhani/nestjs-oop-design-patterns","audit_payload_hash":"2e4aba62ffcd94993d639ea9a7890730","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"c97a1862d1bc82763903ee068cd15acab35d638c","contentHash":"4489d01ab4098d6908dc095d84621b9281e8574b9ac76d591a70972fbc1a4afe","treeHash":"180bcbf3e6e8054316a23f78f580d8fabf23562d375bfd23713824680839e123","pluginPath":"skills/amirtaherkhani/nestjs-oop-design-patterns","auditPayloadHash":"2e4aba62ffcd94993d639ea9a7890730"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/amirtaherkhani-nestjs-oop-design-patterns/audits/1/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}