Skills nestjs-professional-software-engineering
๐Ÿ“ฆ

nestjs-professional-software-engineering

v2.0.2 Content revision r1 Safe โš™๏ธ External commands

Build and Verify Maintainable NestJS Software

NestJS changes can introduce incompatible syntax, hidden side effects, and public API regressions. This skill guides repository inspection, focused implementation, and evidence-based verification.

Supports: Claude Codex Code(CC)
๐Ÿฅ‰ 78 Bronze

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "nestjs-professional-software-engineering" from https://skillstore.io/skills/amirtaherkhani-nestjs-professional-software-engineering.md and its manifest at https://skillstore.io/api/skills/amirtaherkhani-nestjs-professional-software-engineering/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "nestjs-professional-software-engineering". Review a proposal that fetches account balances through a property getter.

Expected outcome:

  • Finding: the getter conceals network I/O, latency, and failure from callers.
  • Recommendation: use an explicit asynchronous operation with visible timeout and cancellation controls.
  • Verification plan: cover successful responses, denied access, timeouts, and upstream failures.

Using "nestjs-professional-software-engineering". Plan an additive payment capture helper while retaining the explicit execution API.

Expected outcome:

  • Recommended design: delegate to the existing operation and preserve its result and error contracts.
  • Caller controls: retain idempotency keys, timeout options, and cancellation behavior.
  • Compatibility plan: keep both public forms available and test them against the same observable contract.

Using "nestjs-professional-software-engineering". Explain verification limits when an integration service is unavailable.

Expected outcome:

  • Verification boundary: local unit tests and type checks cannot establish external service compatibility.
  • Remaining evidence: integration and runtime smoke checks require the unavailable service.
  • Reporting rule: distinguish completed checks from blocked checks and do not report unexecuted checks as passed.

Security Audit

Safe
v1 โ€ข 10/4/2026 Open versioned report

All 14 static findings are false positives: Markdown skill names and ordinary API or testing guidance do not execute commands or conduct reconnaissance. The reviewed instructions require scoped changes, script inspection, authorized mutation, and accurate verification reports. No evidence found of prompt injection, credential exfiltration, or malicious intent.

6
Files scanned
453
Lines analyzed
0
Review items
0
False positives ignored
No confirmed security findings were detected by the latest completed static and semantic audit. This does not prove the skill has no side effects.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/amirtaherkhani-nestjs-professional-software-engineering/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/amirtaherkhani-nestjs-professional-software-engineering/security.svg)](https://skillstore.io/skills/amirtaherkhani-nestjs-professional-software-engineering?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/amirtaherkhani-nestjs-professional-software-engineering?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/amirtaherkhani-nestjs-professional-software-engineering/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/amirtaherkhani-nestjs-professional-software-engineering.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

amirtaherkhani. (2026). nestjs-professional-software-engineering security audit report (audit version 1) [Author version 2.0.2]. Skillstore. https://skillstore.io/skills/amirtaherkhani-nestjs-professional-software-engineering/audits/1

BibTeX citation

@techreport{amirtaherkhani-amirtaherkhani-nestjs-professional-software-engineering-2026, author = {amirtaherkhani}, title = {nestjs-professional-software-engineering security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/amirtaherkhani-nestjs-professional-software-engineering/audits/1}, note = {Author version 2.0.2} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "nestjs-professional-software-engineering security audit report (audit version 1)" version: "2.0.2" type: report authors: - name: "amirtaherkhani" date-released: "2026-10-04" url: "https://skillstore.io/skills/amirtaherkhani-nestjs-professional-software-engineering/audits/1" identifiers: - type: other value: "skillstore:amirtaherkhani-nestjs-professional-software-engineering:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
100
Maintainability
87
Content
65
Community
91
Spec Compliance

What You Can Build

Implement an Existing-Service Feature

Add a NestJS feature using nearby patterns, compatible APIs, focused tests, and clear acceptance criteria.

Refine a Public TypeScript API

Evaluate convenience methods while preserving errors, cancellation, idempotency, and compatibility for existing consumers.

Review a High-Risk Change

Inspect behavior and verification gaps without editing files, then distinguish confirmed evidence from assumptions and unavailable checks.

Try These Prompts

Review a Small Service
Review this NestJS service for readability, input validation, and error handling. Inspect nearby conventions and report evidence without editing files.
Fix a Reproducible Bug
Fix [bug] in this NestJS repository. Inspect callers and versions, add a regression test, preserve public behavior, and report executed checks.
Add a Compatible Convenience API
Add [convenience method] alongside the existing explicit API. Compare supported syntax and preserve errors, timeouts, cancellation, and idempotency. Add shared contract tests.
Implement a Cross-Module Feature
Implement [feature] across these NestJS modules. Map ownership, consumers, authorization, transaction boundaries, and migration risks first. Resolve material conflicts before editing. Report verification gaps.

Best Practices

  • Provide acceptance criteria and public compatibility constraints before requesting implementation.
  • Confirm installed versions and inspect project scripts before selecting syntax or running checks.
  • Request focused tests first, then expand verification for security, persistence, concurrency, or cross-module changes.

Avoid

  • Copying newer framework syntax without confirming compiler, runtime, and package support.
  • Hiding network activity, authorization, retries, or state changes behind getters and convenience methods.
  • Weakening checks or reporting unavailable integration tests as successful.

Frequently Asked Questions

Which AI tools can use this skill?
The package declares support for Claude, Codex, and Claude Code.
Does this package include a NestJS application?
No. It contains workflow instructions, reference guidance, agent configuration, and evaluation scenarios.
Can I request a review without file changes?
Yes. The workflow keeps review and diagnosis read-only unless you also authorize implementation.
How does it choose TypeScript or NestJS syntax?
It prioritizes repository conventions, installed toolchain evidence, and official documentation for the relevant versions.
Are the related NestJS skills required?
No. They are optional ownership references used when installed and relevant to the same decision.
What happens when verification cannot run?
The workflow requires reporting blocked checks and missing prerequisites without claiming success or weakening meaningful controls.

Developer Details

License

MIT

Author version

v2.0.2

Skillstore revision

r1

Ref

c97a1862d1bc82763903ee068cd15acab35d638c

Maintenance freshness

10/5/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“ agents/

๐Ÿ“„ openai.yaml

๐Ÿ“ evals/

๐Ÿ“„ evals.json

๐Ÿ“ references/

๐Ÿ“„ implementation-verification.md

๐Ÿ“„ syntactic-sugar.md

๐Ÿ“„ syntax-and-idioms.md

๐Ÿ“„ SKILL.md

More from amirtaherkhani

View all
View all