Agent skill

Nodejs Best Practices

by ever-works in ever-works/ever-works

Node.js development principles and decision-making. An agent skill from ever-works/ever-works.

AGPL-3.0Auto-check passedDevelopment

Install Nodejs Best Practices

skills CLI
$ npx skills add ever-works/ever-works --skill nodejs-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ever-works/ever-works nodejs-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ever-works/ever-works.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/nodejs-best-practices .claude/skills/nodejs-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nodejs-best-practices
GitHub stars
158
Used in
10 other repos
Token cost
~2.2k tokens
SKILL.md length
608 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
AGPL-3.0

At a glance

Node.js development principles and decision-making. An agent skill from ever-works/ever-works.

  • Works in 10 steps: Framework Selection (2025) → Runtime Considerations (2025) → Architecture Principles → …
  • Tasks that involve Security review
  • SKILL.md covers When to Use, ⚠️ How to Use This Skill, 1. Framework Selection (2025) and 2. Runtime Considerations (2025), plus 5 more sections
  • Calls node

What it does

Nodejs Best Practices is an agent skill from ever-works/ever-works. Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Security review. It works with Node.js and TypeScript. The repository describes itself as: Ever® Works™ - The Workshop for AI. An open agentic runtime that autonomously researches, ships, and maintains entire businesses, 24/7 - https://ever.works. The licence is AGPL-3.0.

When your agent uses it

  • Tasks that involve Security review

Example prompts

  • “/nodejs-best-practices”

Requirements

  • Node.js

Workflow steps

10 steps, taken from the step headings in SKILL.md.

  1. Framework Selection (2025)
  2. Runtime Considerations (2025)
  3. Architecture Principles
  4. Error Handling Principles
  5. Async Patterns Principles
  6. Validation Principles
  7. Security Principles
  8. Testing Principles
  9. Anti-Patterns to Avoid
  10. Decision Checklist

What it can do on your machine

Read from SKILL.md and the folder at commit 11d15aa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nodejs Best Practices loads about 2.2k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 608 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ever-works/ever-works at commit 11d15aa, republished under its AGPL-3.0 licence (© ever-works). 608 words, ~2,184 tokens.

Download SKILL.mdSave it as .claude/skills/nodejs-best-practices/SKILL.md (or your agent's skills folder).
name
nodejs-best-practices
description
Node.js development principles and decision-making. Framework selection, async patterns, security, and architecture. Teaches thinking, not copying.
risk
unknown
source
community
date_added
2026-02-27

Node.js Best Practices

Principles and decision-making for Node.js development in 2025. Learn to THINK, not memorize code patterns.

When to Use

Use this skill when making Node.js architecture decisions, choosing frameworks, designing async patterns, or applying security and deployment best practices.


⚠️ How to Use This Skill

This skill teaches decision-making principles, not fixed code to copy.

  • ASK user for preferences when unclear
  • Choose framework/pattern based on CONTEXT
  • Don't default to same solution every time

1. Framework Selection (2025)

Decision Tree
What are you building?
│
├── Edge/Serverless (Cloudflare, Vercel)
│   └── Hono (zero-dependency, ultra-fast cold starts)
│
├── High Performance API
│   └── Fastify (2-3x faster than Express)
│
├── Enterprise/Team familiarity
│   └── NestJS (structured, DI, decorators)
│
├── Legacy/Stable/Maximum ecosystem
│   └── Express (mature, most middleware)
│
└── Full-stack with frontend
    └── Next.js API Routes or tRPC
Comparison Principles
FactorHonoFastifyExpress
Best forEdge, serverlessPerformanceLegacy, learning
Cold startFastestFastModerate
EcosystemGrowingGoodLargest
TypeScriptNativeExcellentGood
Learning curveLowMediumLow
Selection Questions to Ask:
  1. What's the deployment target?
  2. Is cold start time critical?
  3. Does team have existing experience?
  4. Is there legacy code to maintain?

2. Runtime Considerations (2025)

Native TypeScript
Node.js 22+: --experimental-strip-types
├── Run .ts files directly
├── No build step needed for simple projects
└── Consider for: scripts, simple APIs
Module System Decision
ESM (import/export)
├── Modern standard
├── Better tree-shaking
├── Async module loading
└── Use for: new projects

CommonJS (require)
├── Legacy compatibility
├── More npm packages support
└── Use for: existing codebases, some edge cases
Runtime Selection
RuntimeBest For
Node.jsGeneral purpose, largest ecosystem
BunPerformance, built-in bundler
DenoSecurity-first, built-in TypeScript

3. Architecture Principles

Layered Structure Concept
Request Flow:
│
├── Controller/Route Layer
│   ├── Handles HTTP specifics
│   ├── Input validation at boundary
│   └── Calls service layer
│
├── Service Layer
│   ├── Business logic
│   ├── Framework-agnostic
│   └── Calls repository layer
│
└── Repository Layer
    ├── Data access only
    ├── Database queries
    └── ORM interactions
Why This Matters:
  • Testability: Mock layers independently
  • Flexibility: Swap database without touching business logic
  • Clarity: Each layer has single responsibility
When to Simplify:
  • Small scripts → Single file OK
  • Prototypes → Less structure acceptable
  • Always ask: "Will this grow?"

4. Error Handling Principles

Centralized Error Handling
Pattern:
├── Create custom error classes
├── Throw from any layer
├── Catch at top level (middleware)
└── Format consistent response
Error Response Philosophy
Client gets:
├── Appropriate HTTP status
├── Error code for programmatic handling
├── User-friendly message
└── NO internal details (security!)

Logs get:
├── Full stack trace
├── Request context
├── User ID (if applicable)
└── Timestamp
Status Code Selection
SituationStatusWhen
Bad input400Client sent invalid data
No auth401Missing or invalid credentials
No permission403Valid auth, but not allowed
Not found404Resource doesn't exist
Conflict409Duplicate or state conflict
Validation422Schema valid but business rules fail
Server error500Our fault, log everything

5. Async Patterns Principles

When to Use Each
PatternUse When
async/awaitSequential async operations
Promise.allParallel independent operations
Promise.allSettledParallel where some can fail
Promise.raceTimeout or first response wins
Event Loop Awareness
I/O-bound (async helps):
├── Database queries
├── HTTP requests
├── File system
└── Network operations

CPU-bound (async doesn't help):
├── Crypto operations
├── Image processing
├── Complex calculations
└── → Use worker threads or offload
Avoiding Event Loop Blocking
  • Never use sync methods in production (fs.readFileSync, etc.)
  • Offload CPU-intensive work
  • Use streaming for large data

6. Validation Principles

Validate at Boundaries
Where to validate:
├── API entry point (request body/params)
├── Before database operations
├── External data (API responses, file uploads)
└── Environment variables (startup)
Validation Library Selection
LibraryBest For
ZodTypeScript first, inference
ValibotSmaller bundle (tree-shakeable)
ArkTypePerformance critical
YupExisting React Form usage
Validation Philosophy
  • Fail fast: Validate early
  • Be specific: Clear error messages
  • Don't trust: Even "internal" data

Show full SKILL.md (236 more words)Show less

7. Security Principles

Security Checklist (Not Code)
  • Input validation: All inputs validated
  • Parameterized queries: No string concatenation for SQL
  • Password hashing: bcrypt or argon2
  • JWT verification: Always verify signature and expiry
  • Rate limiting: Protect from abuse
  • Security headers: Helmet.js or equivalent
  • HTTPS: Everywhere in production
  • CORS: Properly configured
  • Secrets: Environment variables only
  • Dependencies: Regularly audited
Security Mindset
Trust nothing:
├── Query params → validate
├── Request body → validate
├── Headers → verify
├── Cookies → validate
├── File uploads → scan
└── External APIs → validate response

8. Testing Principles

Test Strategy Selection
TypePurposeTools
UnitBusiness logicnode:test, Vitest
IntegrationAPI endpointsSupertest
E2EFull flowsPlaywright
What to Test (Priorities)
  1. Critical paths: Auth, payments, core business
  2. Edge cases: Empty inputs, boundaries
  3. Error handling: What happens when things fail?
  4. Not worth testing: Framework code, trivial getters
Built-in Test Runner (Node.js 22+)
node --test src/**/*.test.ts
├── No external dependency
├── Good coverage reporting
└── Watch mode available

10. Anti-Patterns to Avoid

❌ DON'T:
  • Use Express for new edge projects (use Hono)
  • Use sync methods in production code
  • Put business logic in controllers
  • Skip input validation
  • Hardcode secrets
  • Trust external data without validation
  • Block event loop with CPU work
✅ DO:
  • Choose framework based on context
  • Ask user for preferences when unclear
  • Use layered architecture for growing projects
  • Validate all inputs
  • Use environment variables for secrets
  • Profile before optimizing

11. Decision Checklist

Before implementing:

  • Asked user about stack preference?
  • Chosen framework for THIS context? (not just default)
  • Considered deployment target?
  • Planned error handling strategy?
  • Identified validation points?
  • Considered security requirements?

Remember: Node.js best practices are about decision-making, not memorizing patterns. Every project deserves fresh consideration based on its requirements.

© ever-works, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/nodejs-best-practices of ever-works/ever-works.

Open the folder on GitHubat commit 11d15aa

Used in 10 other repositories

We found 23 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 10 other GitHub owners. This page covers the copy in ever-works/ever-works, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Nodejs Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nodejs Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nodejs Best Practices this skillever-works/ever-works15810 repos~2.2kAutomated safety check: PassAGPL-3.0
Typescript Security Reviewgiuseppe-trisciuoglio/developer-kit355—~2.4kAutomated safety check: NotesMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Generate Release Notesteambit/bit18k—~2.2kAutomated safety check: PassCustom licence
Add NodeBridge Handlerneovateai/neovate-code1.6k—~1kAutomated safety check: PassMIT
ast-grep Codemod Referencewarp-drive-data/warp-drive3.2k—~2.6kAutomated safety check: PassMIT

Similar skills

  • Typescript Security Review

    giuseppe-trisciuoglio/developer-kit

    Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure.

    355 GitHub stars~2.4k tokensUpdated 27 days ago
    SecurityAuto-check: notes
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Generate comprehensive release notes for Bit from git commits and pull requests.

    18k GitHub stars~2.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Add NodeBridge Handler

    neovateai/neovate-code

    Walks through adding a message handler to NodeBridge in Neovate Code, from the implementation and its types to an optional test entry and a run with Bun.

    1.6k GitHub stars~1k tokensUpdated 6 mo ago
    DevelopmentAuto-check passed
  • ast-grep Codemod Reference

    warp-drive-data/warp-drive

    Reference for writing and debugging TypeScript and JavaScript codemods with @ast-grep/napi: parsing, node queries, meta-variables, rule objects and editing.

    3.2k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Coding Standards

    kurealnum/dotfiles

    Universal coding standards, best practices, and patterns for TypeScript, JavaScript, React, and Node.js development.

    290 GitHub starsUsed in 17 repos~2.9k tokens
    DevelopmentAuto-check passed

More from ever-works/ever-works

All 14 skills in this repo
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 17 repos~4k tokens
    Auto-check passed
  • Accessibility

    ever-works/ever-works

    Audit and improve web accessibility following WCAG 2.2 guidelines.

    158 GitHub starsUsed in 6 repos~3.2k tokens
    Auto-check passed
  • Tailwind CSS Patterns

    ever-works/ever-works

    Provides comprehensive Tailwind CSS utility-first styling patterns including responsive design, layout utilities, flexbox, grid, spacing, typography, colors, and modern CSS best practices.

    158 GitHub starsUsed in 3 repos~1.6k tokens
    Auto-check: notes
  • SEO

    ever-works/ever-works

    Optimize for search engine visibility and ranking. An agent skill from ever-works/ever-works.

    158 GitHub starsUsed in 10 repos~2.9k tokens
    Auto-check passed
  • Nodejs Express Server

    ever-works/ever-works

    Build production-ready Express.js servers with middleware, authentication, routing, and database integration.

    158 GitHub stars~965 tokensUpdated 2 days ago
    Auto-check passed
  • Tailwind V4 Shadcn

    ever-works/ever-works

    Production-tested setup for Tailwind CSS v4 with shadcn/ui, Vite, and React.

    158 GitHub starsUsed in 2 repos~3.8k tokens
    Auto-check passed

Categories

Questions about Nodejs Best Practices

What does Nodejs Best Practices do?

Node.js development principles and decision-making. An agent skill from ever-works/ever-works. Nodejs Best Practices is an agent skill from ever-works/ever-works.js development principles and decision-making.

When should I use Nodejs Best Practices?

Nodejs Best Practices fits situations like: tasks that involve Security review.

How do I install Nodejs Best Practices in Claude Code?

Run `npx skills add ever-works/ever-works --skill nodejs-best-practices -a claude-code`. Or copy the skill folder (.agents/skills/nodejs-best-practices in ever-works/ever-works) into .claude/skills/nodejs-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Nodejs Best Practices in Codex?

Run `npx skills add ever-works/ever-works --skill nodejs-best-practices -a codex`. Or copy the skill folder (.agents/skills/nodejs-best-practices in ever-works/ever-works) into .agents/skills/nodejs-best-practices in your project. Codex loads it when a task matches its description.

Can I use Nodejs Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ever-works/ever-works --skill nodejs-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nodejs-best-practices, .gemini/skills/nodejs-best-practices, .github/skills/nodejs-best-practices and .opencode/skills/nodejs-best-practices in your project.

What does Nodejs Best Practices need to run?

Going by SKILL.md and its folder, Nodejs Best Practices needs the command-line tools its instructions call (node). Our summary lists: Node.js.

Does Nodejs Best Practices access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nodejs Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nodejs Best Practices use?

Nodejs Best Practices is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nodejs Best Practices use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nodejs Best Practices?

Skills that share tags, products or a category with Nodejs Best Practices: Typescript Security Review (giuseppe-trisciuoglio/developer-kit, 355 stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Generate Release Notes (teambit/bit, 18k stars) and Add NodeBridge Handler (neovateai/neovate-code, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nodejs Best Practices?

ever-works (a GitHub organization) maintains it in ever-works/ever-works, which has 158 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 5, 2026.

Source: ever-works/ever-works on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.