Agent skill

Nestjs

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when building or structuring a NestJS backend — feature modules, providers and DI wiring, provider scopes and request-lifecycle order, where to bind…

MITAuto-check passedBackend & APIs

Install Nestjs

skills CLI
$ npx skills add ericrisco/rsc-harness --skill nestjs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness nestjs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/nestjs .claude/skills/nestjs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nestjs
GitHub stars
167
Token cost
~2.9k tokens
SKILL.md length
1,137 words
Files
6 (incl. scripts, references)
Skills in repo
227
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when building or structuring a NestJS backend — feature modules, providers and DI wiring, provider scopes and request-lifecycle order, where to bind…

  • Structuring a NestJS backend — feature modules
  • SKILL.md covers Not this — route instead, Mental model, Module design and Providers & DI, plus 7 more sections
  • Runs Shell scripts from its folder; needs STRIPE_KEY
  • Providers and DI wiring

What it does

Nestjs is an agent skill from ericrisco/rsc-harness. Use when building or structuring a NestJS backend — feature modules, providers and DI wiring, provider scopes and request-lifecycle order, where to bind guards/pipes/interceptors/filters, and testing with Test.createTestingModule. NOT a bare Express/Fastify service with no DI (that is nodejs), NOT framework-agnostic REST design (that is api-design).

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/cross-cutting.md`).

It sits in Backend & APIs, covering API design. It works with NestJS, Fastify and Node.js. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Structuring a NestJS backend — feature modules
  • Providers and DI wiring
  • Provider scopes and request-lifecycle order
  • Where to bind guards/pipes/interceptors/filters

Example prompts

  • “/nestjs”

Requirements

  • Node.js
  • A Bash shell
  • A credential in STRIPE_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit e3d5b33. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • STRIPE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nestjs loads about 2.9k tokens when it runs, and up to ~5.1k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 1,137 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit e3d5b33, republished under its MIT licence (© ericrisco). 1,137 words, ~2,928 tokens.

Download SKILL.mdSave it as .claude/skills/nestjs/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
nestjs
description
Use when building or structuring a NestJS backend — feature modules, providers and DI wiring, provider scopes and request-lifecycle order, where to bind guards/pipes/interceptors/filters, and testing with Test.createTestingModule. NOT a bare Express/Fastify service with no DI (that is `nodejs`), NOT framework-agnostic REST design (that is `api-design`).
tags
nestjs, nodejs, backend, dependency-injection, guards, pipes, testing, typescript
recommends
nodejs, typescript, api-design, prisma-orm, testing-web
origin
risco

NestJS

Build server-side Node apps the way NestJS intends: feature modules, providers wired through the DI container, controllers, and a cross-cutting layer bound at a deliberate scope. This skill is about Nest-specific mechanics — how DI scopes resolve, what order the request lifecycle runs in, where to bind guards/pipes/interceptors/filters, and how to test it with Test.createTestingModule.

Not this — route instead

  • Bare Express/Fastify/http service, no @Module/@Injectable → ../nodejs/SKILL.md. Nest starts the moment the DI container appears.
  • REST resource modeling, versioning, status codes, idempotency (framework-agnostic) → ../api-design/SKILL.md. Nest is where you implement those decisions.
  • Designing the schema / writing queries / migrations → ../prisma-orm/SKILL.md. Injecting a repo or DataSource provider stays here; designing the table does not.
  • Generic JS/TS test infra (Jest config, coverage thresholds, monorepo) → ../testing-web/SKILL.md. The Nest harness (TestingModule, overrideProvider, Supertest bootstrap) stays here.

Mental model

Everything is a provider in a directed DI graph. Modules draw the boundaries of that graph — a provider is only reachable where it is provided or imported. Cross-cutting concerns (guards, interceptors, pipes, filters) are decorators bound at a scope you choose: global, controller, or route. Get those three right and the rest is plumbing.

The request lifecycle runs in a fixed order. Memorize it — most "my guard can't see the validated body" bugs are an ordering misunderstanding:

text
req → middleware → guards → interceptors(pre) → pipes → handler → interceptors(post) → exception filters → res

So pipes run after guards (a guard cannot read a transformed DTO), and filters catch everything thrown downstream. Source: NestJS request-lifecycle docs.

Module design

One feature module per bounded context. Rules, each with its why:

  • exports is the module's public API. A provider not exported is private to that module — that is the encapsulation, lean on it.
  • imports brings in another module's exports; it does not re-declare providers. Re-declaring a provider in two modules gives you two singletons and silent state bugs.
  • Keep AppModule thin. It wires feature modules and global config, nothing else. A god AppModule that declares every controller becomes an untestable circular-dependency magnet.
  • Use a dynamic module (forRoot / forRootAsync) for configurable infrastructure (DB, cache, mailer) so consumers pass options instead of editing the module.
typescript
// Bad — everything dumped in AppModule, no boundaries
@Module({ controllers: [OrdersController, UsersController, BillingController],
          providers: [OrdersService, UsersService, BillingService, PrismaService] })
export class AppModule {}

// Good — a feature module owns its slice and exports only its public surface
@Module({
  imports: [PrismaModule],
  controllers: [OrdersController],
  providers: [OrdersService],
  exports: [OrdersService], // other modules consume the service, not the repo
})
export class OrdersModule {}

Providers & DI

Pick the custom-provider form by intent:

FormUse it whenResolved by
useClassDefault — swap implementation by class (e.g. real vs fake mailer)Nest instantiates
useValueA ready object/constant: config, a mock in testsUsed as-is
useFactoryValue needs computing or other providers (inject: [...])Your factory fn
useExistingAlias an existing token to a new tokenReuses instance

A non-class token needs explicit injection — Nest has no type to reflect on:

typescript
const STRIPE = 'STRIPE_CLIENT';

@Module({
  providers: [{
    provide: STRIPE,
    useFactory: (cfg: ConfigService) => new Stripe(cfg.get('STRIPE_KEY')),
    inject: [ConfigService],
  }],
  exports: [STRIPE],
})
export class PaymentsModule {}

@Injectable()
export class CheckoutService {
  constructor(@Inject(STRIPE) private readonly stripe: Stripe) {}
}

forwardRef(() => X) is a last resort, not a fix — it works around a circular dependency that usually signals two modules that should share a third. Reach for the refactor first; if you must, forwardRef goes on both sides. See the anti-patterns table.

Provider scopes

ScopeLifetimeUse when
DEFAULTSingleton (one per app)Almost always — stateless services
REQUESTNew instance per requestYou genuinely need per-request state (@Inject(REQUEST) for the live request)
TRANSIENTNew instance per consumerEach injector gets its own copy

REQUEST scope bubbles up: any provider that injects a request-scoped provider becomes request-scoped too, and so does the controller — with a real per-request instantiation cost. Default to singleton; reach for REQUEST only when you must.

typescript
@Injectable({ scope: Scope.REQUEST })
export class RequestContext {
  constructor(@Inject(REQUEST) private readonly req: Request) {}
  get userId() { return this.req.user?.id; }
}

The classic gotcha: a request-scoped provider injected into a guard reads as undefined or stale because guards run early and the scope propagation is not what you assumed. If a guard needs request data, pull it from ExecutionContext (context.switchToHttp().getRequest()), not from an injected request-scoped service.

Cross-cutting layer

Pick the primitive by what it is for:

PrimitiveJobSignature
GuardAuthorize — allow/deny the requestreturns boolean / Promise<boolean>
InterceptorWrap the handler before and after (logging, transform, timeout, cache)RxJS, handle().pipe(...)
PipeValidate and/or transform an input argumentreturns transformed value or throws
Exception filterCatch a thrown error and shape the responsecatch(exception, host)

Then pick the binding scope:

BindingReachCan inject deps?
APP_GUARD / APP_PIPE / APP_INTERCEPTOR / APP_FILTER token in a module's providersGlobalYes — resolved by the DI container
@UseGuards(X) / @UsePipes(X) on controller or routeLocalYes if you pass the class
app.useGlobalGuards(new X()) in main.tsGlobalNo — you instantiated it yourself

The gotcha that bites everyone: app.useGlobalPipes(new ValidationPipe()) works, but a guard or pipe that needs to inject a ConfigService cannot be registered with new — Nest never resolved it. Use the APP_* token instead so the container builds it:

typescript
// Good — global AND DI-capable
@Module({
  providers: [{ provide: APP_GUARD, useClass: AuthGuard }],
})
export class AppModule {}

Deeper material — ExecutionContext, custom param decorators, Reflector + SetMetadata for role/@Public() guards, transform/timeout interceptors, filter shape, multiple-binding order — is in references/cross-cutting.md.

Show full SKILL.md (402 more words)Show less

Validation

DTO + ValidationPipe + class-validator/class-transformer. The production-safe config:

typescript
// main.ts
app.useGlobalPipes(new ValidationPipe({
  whitelist: true,            // strip properties with no decorator
  forbidNonWhitelisted: true, // 400 on unknown properties instead of silently dropping
  transform: true,            // coerce payloads to DTO class instances (and primitives)
}));
typescript
export class CreateOrderDto {
  @IsString() @IsNotEmpty()
  sku: string;

  @IsInt() @Min(1)
  quantity: number;
}

If the pipe needs to inject something, bind it globally via APP_PIPE instead of new (same DI rule as above).

Testing

Test.createTestingModule({...}).compile() returns a TestingModule you pull providers from. Decision line: unit-test a provider with its collaborators mocked; e2e-test the wired app over HTTP.

Unit — mock the collaborators:

typescript
const moduleRef = await Test.createTestingModule({
  providers: [OrdersService],
})
  .overrideProvider(OrderRepository)
  .useValue({ findById: vi.fn().mockResolvedValue(order) })
  .compile();

const service = moduleRef.get(OrdersService);

e2e — boot the real app and hit it with Supertest. Replicate the global config from main.ts (pipes, filters, guards) or the test passes while prod 400s:

typescript
const app = moduleRef.createNestApplication();
app.useGlobalPipes(new ValidationPipe({ whitelist: true, transform: true })); // mirror main.ts
await app.init();
await request(app.getHttpServer()).post('/orders').send(body).expect(201);

overrideGuard(AuthGuard).useValue({ canActivate: () => true }) lets an e2e test bypass auth. Full recipes — mocking a repo, request-scoped via resolve(), ConfigModule in tests, Vitest vs Jest — in references/testing-recipes.md.

Bootstrap & tooling

  • Scaffold with the CLI, not by hand: nest g resource orders, nest g module orders, nest g service orders. It wires the module registration for you.
  • NestJS 11 is current (Jan 2025), requires Node.js 20+, and ships Express v5 as the default HTTP adapter (Fastify remains an option).
  • Use the SWC builder for dev — roughly 20x faster builds and faster cold start than tsc. Keep tsc for type-checking in CI.
  • ESM is first-class in v11 (top-level await aligned with modern Node).
  • The official harness is moving toward Vitest (SWC-powered) alongside Jest; Jest is still fully supported and is what nest new historically scaffolds.

Anti-patterns

Anti-patternWhy it hurtsDo instead
God AppModule declaring every controller/providerNo boundaries; breeds circular deps; untestableOne feature module per bounded context, exports = public API
new OrdersService(repo) inside a controller/serviceBypasses DI; same class becomes two unmocked instancesConstructor-inject; let the container build it
Business logic in the controllerControllers should map HTTP ↔ service calls onlyPush logic into a provider; controller stays thin
Scope.REQUEST by defaultBubbles up the chain, per-request cost, surprise undefined in guardsDefault singleton; REQUEST only with a real reason
useGlobalPipes(new X()) for a pipe that needs depsnew is not DI-resolved; injected deps are undefinedBind via APP_PIPE / APP_GUARD token in providers
e2e test that skips main.ts globalsGreen test, red prod — validation/filters not appliedReplicate global pipes/filters/guards in the e2e bootstrap
forwardRef sprinkled to silence "circular dependency"Hides the real coupling; fragile bootstrap orderRefactor to a shared module; forwardRef only as last resort, on both sides

Verify

Run scripts/verify.sh [dir] to statically catch DI bypasses without a Nest install. It hard-fails only on new XxxService(...) outside test files; everything else is a warning. Exits 0 on a clean or empty target.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/nestjs of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/cross-cutting.md
  • references/testing-recipes.md
  • scripts/verify.sh

Open the folder on GitHubat commit e3d5b33

Compare with similar skills

Nestjs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nestjs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nestjs this skillericrisco/rsc-harness167—~2.9kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works15818 repos~4kAutomated safety check: PassAGPL-3.0
Fishjam JS Server SDKsoftware-mansion-labs/skills291—~1.4kAutomated safety check: PassMIT
Backend PatternshellangleZ/burn-in-cceverywhere-ralph11217 repos~3.3kAutomated safety check: PassNone
AI Model NodejsTencentCloudBase/CloudBase-AI-Toolkit1.1k3 repos~5kAutomated safety check: PassMIT
Senior Backendalirezarezvani/claude-skills28k1 repos~3.8kAutomated safety check: PassMIT

Similar skills

  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed
  • Fishjam JS Server SDK

    software-mansion-labs/skills

    Node.js / TypeScript server SDK for Fishjam — backends that create rooms, mint peer tokens, listen to server notifications, and run agents.

    291 GitHub stars~1.4k tokensUpdated 10 days ago
    Backend & APIsAuto-check passed
  • Backend Patterns

    hellangleZ/burn-in-cceverywhere-ralph

    Backend architecture patterns, API design, database optimization, and server-side best practices for Node.js, Express, and Next.js API routes.

    112 GitHub starsUsed in 17 repos~3.3k tokens
    Backend & APIsAuto-check passed
  • AI Model Nodejs

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.

    1.1k GitHub starsUsed in 3 repos~5k tokens
    Backend & APIsAuto-check passed
  • Senior Backend

    alirezarezvani/claude-skills

    Designs and implements backend systems including REST APIs, microservices, database architectures, authentication flows, and security hardening.

    28k GitHub starsUsed in 1 repo~3.8k tokens
    Backend & APIsAuto-check passed
  • Sentry Nestjs SDK

    getsentry/sentry-for-ai

    Official

    Full Sentry SDK setup for NestJS. An agent skill from getsentry/sentry-for-ai.

    268 GitHub stars~8.7k tokensUpdated today
    Backend & APIsAuto-check passed

More from ericrisco/rsc-harness

All 227 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    167 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    167 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    167 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    167 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    167 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    167 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Categories

Questions about Nestjs

What does Nestjs do?

A skill your agent uses when building or structuring a NestJS backend — feature modules, providers and DI wiring, provider scopes and request-lifecycle order, where to bind…. Nestjs is an agent skill from ericrisco/rsc-harness.createTestingModule.

When should I use Nestjs?

Nestjs fits situations like: structuring a NestJS backend — feature modules; providers and DI wiring; provider scopes and request-lifecycle order; where to bind guards/pipes/interceptors/filters.

How do I install Nestjs in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill nestjs -a claude-code`. Or copy the skill folder (skills/nestjs in ericrisco/rsc-harness) into .claude/skills/nestjs in your project. Claude Code loads it when a task matches its description.

How do I install Nestjs in Codex?

Run `npx skills add ericrisco/rsc-harness --skill nestjs -a codex`. Or copy the skill folder (skills/nestjs in ericrisco/rsc-harness) into .agents/skills/nestjs in your project. Codex loads it when a task matches its description.

Can I use Nestjs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill nestjs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nestjs, .gemini/skills/nestjs, .github/skills/nestjs and .opencode/skills/nestjs in your project.

What does Nestjs need to run?

Going by SKILL.md and its folder, Nestjs needs a shell for the scripts in its folder and credentials named STRIPE_KEY. Our summary lists: Node.js; A Bash shell; A credential in STRIPE_KEY.

Does Nestjs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nestjs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Nestjs use?

Nestjs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nestjs use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.1k tokens, read only when the agent opens those files.

What are the alternatives to Nestjs?

Skills that share tags, products or a category with Nestjs: Nodejs Backend Patterns (ever-works/ever-works, 158 stars), Fishjam JS Server SDK (software-mansion-labs/skills, 291 stars), Backend Patterns (hellangleZ/burn-in-cceverywhere-ralph, 112 stars) and AI Model Nodejs (TencentCloudBase/CloudBase-AI-Toolkit, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nestjs?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 167 GitHub stars. The repository holds 227 skills in this directory. The repository was last updated on October 7, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.