# Audit NestJS Features Against Their Roadmaps

Source code alone cannot establish whether a NestJS feature satisfies its roadmap. This skill compares requirements with revision-specific evidence and reports completed work, gaps, legacy paths, bugs, and blockers.

## Install

```bash
npx skillstore add amirtaherkhani/nestjs-feature-audit
```

## Metadata

- Status: approved
- Slug: amirtaherkhani-nestjs-feature-audit
- Version: 1.0.2
- Author version: 1.0.2
- Skillstore revision: r1
- Version status: valid
- Tree hash: 37d714c7cad4b8ef7bfaac5d0915194ea46267dceef1f2770017a02022b56700
- Author: amirtaherkhani
- GitHub username: amirtaherkhani
- License: MIT
- Repository: https://github.com/amirtaherkhani/nestjs-skills/tree/b82cdf0312e1c1bcaf871bb67473e91b2a1befad/skills/nestjs-feature-audit
- Ref: c97a1862d1bc82763903ee068cd15acab35d638c
- Supported tools: Claude, Codex, Claude Code
- Audit status: complete
- Agent install advisory: allowed
- Manual install advisory: allowed
- Artifact signature: available
- Audit attestation: unavailable
- Human verification: not\_verified
- Risk factors: external\_commands
- Quality score: 78
- Quality tier: bronze
- Public page: https://skillstore.pages.dev/skills/amirtaherkhani-nestjs-feature-audit
- Manifest: https://skillstore.pages.dev/api/skills/amirtaherkhani-nestjs-feature-audit/manifest

## Capabilities

- Record the audited branch, commit, worktree state, remote revision, and freshness status.
- Find roadmap candidates and stop when no clear, authoritative feature target is available.
- Trace roadmap requirements to source, tests, configuration, migrations, contracts, and available runtime evidence.
- Classify requirements as verified, partial, absent, superseded, broken, blocked, or not verifiable.
- Produce four report sections covering implementation, missing work, legacy code, and bugs or blockers.
- Separate implemented source from unverified rollout requirements and document the next required proof.

## Use Cases

- Check Release Readiness: Compare a feature on a release branch with its acceptance plan and identify missing evidence before approval.
- Review Migration Progress: Identify active legacy paths, replacement coverage, and rollout prerequisites against a documented migration roadmap.
- Plan Acceptance Validation: Map roadmap requirements to tests and observed behavior, then list the checks needed to resolve unverified items.

## Prompt Templates

### Audit One Feature

```
Audit the payments feature against its documented roadmap on main. Return the evidence-backed report without implementing fixes.
```

### Review a Release Branch

```
Audit subscriptions on branch release/subscriptions against the documented acceptance plan. Record revision freshness and cite evidence for each requirement. Do not implement fixes.
```

### Assess a Migration

```
Audit internal-events against its migration roadmap on main. Separate replacement code, active legacy paths, and production cutover prerequisites. Report exit evidence without deploying.
```

### Build Detailed Acceptance Traceability

```
Audit refunds on branch release/refunds using the attached roadmap as the authoritative target. Trace each acceptance condition across source, wiring, tests, configuration, and available runtime evidence. Deduplicate findings and identify next validation steps. Do not mutate implementation or publish changes.
```

## Limitations

- Requires Git, a NestJS repository, and a clear roadmap in repository documentation or supplied by the user.
- Remote freshness verification requires network access; unavailable remotes require explicit acceptance of a local snapshot.
- Runtime, deployment, and external-system claims remain unverified without safe access and supporting evidence.
- Does not implement fixes, publish changes, deploy, or edit roadmaps as part of an audit alone.

## Best Practices

- Name the feature, target branch, and authoritative roadmap before requesting comparison.
- Keep the worktree clean and approve any local-snapshot exception explicitly when remote freshness cannot be verified.
- Review each requirement citation and next-proof step before treating implemented source as production completion.

## Anti Patterns

- Treating a TODO mention or existing source code as the feature roadmap.
- Interpreting unavailable tests, missing runtime access, or unperformed deployment checks as verified success.
- Using an audit request as permission to implement fixes, publish changes, or deploy.

## Security Audit

- Audited at: 2026-10-04T20:39:22.991\+00:00
- Summary: All 35 static findings are false positives: Markdown backticks were mistaken for execution, and a reporting heading was mistaken for system reconnaissance. No evidence found of prompt injection, data exfiltration, or malicious intent in the reviewed files. The workflow includes remote fetch, branch switching, and fast-forward updates, with explicit worktree safeguards and no automatic fixes or publication.

## Stats

- Views: 0
- Downloads: 0
- Favorites: 0
- Popularity score: 0
