Agent skill

Nodejs

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when building or operating a plain Node.js / Express 5 backend service: project layout, async correctness, central error middleware, fail-fast config, graceful shutdown on…

MITAuto-check passedBackend & APIs

Install Nodejs

skills CLI
$ npx skills add ericrisco/rsc-harness --skill nodejs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness nodejs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/nodejs .claude/skills/nodejs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nodejs
GitHub stars
167
Token cost
~3.2k tokens
SKILL.md length
1,086 words
Files
6 (incl. scripts, references)
Skills in repo
227
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when building or operating a plain Node.js / Express 5 backend service: project layout, async correctness, central error middleware, fail-fast config, graceful shutdown on…

  • Works in 5 steps: Flip readiness to not-ready so the load… → server.close() — stop accepting new… → Abort long-running work via a shared… → …
  • Operating a plain Node.js / Express 5 backend service: project layout
  • SKILL.md covers Boundary, Decide first, Project layout and Async rules, plus 6 more sections
  • Runs Shell scripts from its folder; calls node

What it does

Nodejs is an agent skill from ericrisco/rsc-harness. Use when building or operating a plain Node.js / Express 5 backend service: project layout, async correctness, central error middleware, fail-fast config, graceful shutdown on SIGTERM. NOT DI modules/providers/guards (that is nestjs), NOT the type system or tsconfig (that is typescript), NOT REST contract design (that is api-design).

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/express5-migration.md`).

It sits in Backend & APIs, covering API design. It works with Node.js, TypeScript and NestJS. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Operating a plain Node.js / Express 5 backend service: project layout
  • Async correctness
  • Central error middleware
  • Fail-fast config

Example prompts

  • “/nodejs”

Requirements

  • Node.js
  • A Bash shell
  • Docker

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Flip readiness to not-ready so the load balancer stops routing new traffic.
  2. server.close() — stop accepting new connections, let in-flight requests finish.
  3. Abort long-running work via a shared AbortController (the signal you threaded into ops).
  4. Close the DB pool and other resources.
  5. process.exit(0), with a force-exit timer as a backstop if drain stalls.

What it can do on your machine

Read from SKILL.md and the folder at commit e3d5b33. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nodejs loads about 3.2k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 87 tokens; SKILL.md has 1,086 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~87
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit e3d5b33, republished under its MIT licence (© ericrisco). 1,086 words, ~3,188 tokens.

Download SKILL.mdSave it as .claude/skills/nodejs/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
nodejs
description
Use when building or operating a plain Node.js / Express 5 backend service: project layout, async correctness, central error middleware, fail-fast config, graceful shutdown on SIGTERM. NOT DI modules/providers/guards (that is `nestjs`), NOT the type system or tsconfig (that is `typescript`), NOT REST contract design (that is `api-design`).
tags
nodejs, express, backend, async, error-handling
recommends
nestjs, typescript, api-design, error-handling, postgresdb
origin
risco

Node.js backend services

Stand up a plain Node.js HTTP/JSON service — node:http or Express 5 — that a person can read, test, and operate without a DI framework. This skill is about the runtime and the request lifecycle: how to lay out the code, how to keep async correct, how errors become status codes, how config fails fast, and how the process dies cleanly. The contract shape, the type system, and the data layer live elsewhere (see the boundary below).

Boundary

  • The app is built around @Module / @Injectable / DI providers, guards, interceptors, pipes, exception filters → nestjs. Nest starts the moment the DI container appears; route away then, do not half-build it here.
  • Pure TypeScript type system, generics, tsconfig → typescript. This skill uses TS but does not teach types.
  • REST resource modeling, versioning, pagination, status-code semantics (framework-agnostic) → api-design. This skill wires the handlers; api-design decides the contract. Cross-cutting error taxonomy → error-handling.
  • Schema, queries, connection pool, migrations → postgresdb / prisma-orm / drizzle-orm. Calling a repository stays here; designing the table does not.
  • Containerizing / shipping → docker / deployment. Choosing the logging/metrics/tracing stack → observability. This skill emits structured logs and a shutdown hook; it does not own the pipeline.

Decide first

Pick the runtime shape before writing code — the wrong choice is expensive to undo.

SituationChoiceWhy
Needs DI/modules, large team, heavy cross-cuttingroute to nestjsDon't reinvent a DI container by hand
Small/medium JSON API, want middleware + routingExpress 5Mature, async errors auto-forward (v5)
One tiny endpoint, zero deps, a healthchecknode:httpNo dependency surface to maintain
A library, not a servernot this skillNo request lifecycle to manage

Defaults for a new service: pin Node 24 (Active LTS) in engines.node; Node 22 is Maintenance LTS; Node 26 is Current (released 2026-05-05, enters LTS Oct 2026) — adopt it only if you want Temporal/V8 14.6 and can track Current. Write ESM for new code ("type": "module"), CommonJS only when a hard dependency forces it.

jsonc
// package.json
{
  "type": "module",
  "engines": { "node": ">=24" },
  "scripts": {
    "dev": "node --watch src/server.ts",
    "test": "node --test"
  }
}

Project layout

Concrete tree. The names are conventions, not magic — but the split is load-bearing.

text
src/
  app.ts          # build + return the Express app; NEVER calls listen()
  server.ts       # imports app, listens, owns SIGTERM/shutdown
  config/
    env.ts        # validate process.env once, export a typed `config`
  routes/
    users.ts      # router only: path → controller
  controllers/
    users.ts      # parse request, call service, shape response
  services/
    users.ts      # business logic, no req/res objects
  repositories/
    users.ts      # data access; the only layer that touches the DB
  errors/
    app-error.ts  # AppError/HttpError with status + code

Rule — separate app construction from listen(). app.ts builds and returns the app; server.ts binds the port and owns shutdown. Why: tests import app and exercise routes in-process without binding a port, so they run fast and in parallel.

ts
// Bad: index.ts listens at import time — untestable, double-binds in tests
const app = express();
app.get("/health", (_req, res) => res.json({ ok: true }));
app.listen(3000); // side effect on import

// Good: app.ts
export function buildApp() {
  const app = express();
  app.get("/healthz", (_req, res) => res.json({ ok: true }));
  return app; // no listen here
}

Async rules

Every async mistake here is a latent production incident, not a style nit.

  • Await or return every promise. A floating promise is a latent process crash — since Node 15 an unhandled rejection terminates the process by default. The error happens later, detached from its handler.
  • Never mix callback + promise styles. Promisify once at the boundary (util.promisify or fs/promises) and stay in promises after that. Half-converted code swallows errors.
  • Promise.all for independent work; sequential await only for true dependencies. Awaiting independent calls one by one wastes wall-clock time.
  • Use AbortSignal.timeout(ms) for per-operation deadlines and thread the signal into fetch/DB/long ops. Compose with AbortController so shutdown can cancel in-flight work (see graceful shutdown).
  • Never rely on a global unhandledRejection handler as control flow. Log and exit there if anything; do not use it to keep running.
ts
// Bad: forgotten await — the rejection floats and crashes later, error lost
function handler(req, res) {
  saveAudit(req.body);          // returns a promise nobody awaits
  res.json({ ok: true });       // responds before save resolves/rejects
}

// Good: await it (Express 5 forwards a throw to the error middleware)
async function handler(req, res) {
  await saveAudit(req.body);
  res.json({ ok: true });
}

Error handling

This is the core, and the most common bug. In Express 5 an async handler that rejects or throws is auto-forwarded to the error middleware — no try/catch + next(err) wrapper, no asyncHandler. Source: Express 5 migration guide and the framework's own router tests (a value-less Promise.reject() becomes an Error with message Rejected promise).

  • Define one AppError (or HttpError) carrying status and code. Throw it from services; controllers don't translate.
  • Register exactly one 4-arg (err, req, res, next) error middleware, LAST, after every route. Arity is what makes Express treat it as an error handler — a 3-arg function is a normal middleware no matter what you name it. Order still matters in v5.
  • A 404 fallthrough handler goes just before the error middleware.
  • Map known errors → their status; unknown → 500; never leak the stack or raw message in production.
ts
// errors/app-error.ts
export class AppError extends Error {
  constructor(public status: number, public code: string, message: string) {
    super(message);
  }
}

// app.ts — registration ORDER (routes → 404 → error handler)
app.use("/users", usersRouter);

app.use((_req, res) => res.status(404).json({ code: "not_found" }));

// LAST, exactly 4 args — this is the error handler
app.use((err, _req, res, _next) => {
  const status = err instanceof AppError ? err.status : 500;
  const code = err instanceof AppError ? err.code : "internal_error";
  if (status >= 500) logger.error({ err }, "unhandled");
  res.status(status).json({
    code,
    message: status < 500 ? err.message : "Internal Server Error",
    ...(process.env.NODE_ENV !== "production" && { stack: err.stack }),
  });
});
ts
// Bad: the symptom "async route throws but client gets 200 empty body"
app.use((err, _req, res, _next) => { /* error handler */ });  // registered FIRST
app.get("/users/:id", async (req, res) => {
  const u = await findUser(req.params.id);   // throws NotFound
  res.json(u);                                // never reached; no handler after → hangs/empties
});

The error handler placed before the route never sees the throw, so the response is whatever was half-written. Put it last. See references/express5-migration.md for the full v4→5 breaking-change checklist, the middleware-order diagram, and the legacy v4 asyncHandler wrapper.

Show full SKILL.md (402 more words)Show less

Config & secrets

Validate process.env once at boot, fail fast, and export a typed config object. A missing variable should crash at startup, not at 3am on first use. Ban scattered process.env.X reads throughout the codebase — they hide the contract and defeat the boot check.

ts
// config/env.ts — hand-rolled or zod/envalid; the point is one gate
import { z } from "zod";
const schema = z.object({
  PORT: z.coerce.number().default(3000),
  DATABASE_URL: z.string().url(),
  NODE_ENV: z.enum(["development", "test", "production"]).default("development"),
});
export const config = schema.parse(process.env); // throws → process won't start

Graceful shutdown

On SIGTERM the orchestrator gives you a brief window to finish. Drop nothing.

  1. Flip readiness to not-ready so the load balancer stops routing new traffic.
  2. server.close() — stop accepting new connections, let in-flight requests finish.
  3. Abort long-running work via a shared AbortController (the signal you threaded into ops).
  4. Close the DB pool and other resources.
  5. process.exit(0), with a force-exit timer as a backstop if drain stalls.

Expose /healthz (liveness — is the process up) separately from /readyz (readiness — should it receive traffic). They answer different questions; conflating them causes both false restarts and dropped requests during deploys. The complete copy-pasteable server.ts — signal handlers, AbortController, readiness gate, force-exit backstop — lives in references/graceful-shutdown.md.

ts
// server.ts (sketch — full version in references/)
const controller = new AbortController();
const server = buildApp().listen(config.PORT);

function shutdown() {
  ready = false;                       // /readyz now 503
  server.close(() => process.exit(0)); // drain, then exit
  controller.abort();                  // cancel in-flight long ops
  setTimeout(() => process.exit(1), 10_000).unref(); // backstop
}
process.on("SIGTERM", shutdown);
process.on("SIGINT", shutdown);

Testing

Node 24 ships a built-in test runner — node:test with node --test — so a backend needs no external runner for unit/integration tests, and node --watch for dev. Import app from app.ts and hit it directly (supertest or undici); never start the live server in a test. That is exactly why app.ts doesn't call listen().

ts
import { test } from "node:test";
import assert from "node:assert/strict";
import request from "supertest";
import { buildApp } from "../src/app.ts";

test("404 returns the error contract", async () => {
  const res = await request(buildApp()).get("/nope");
  assert.equal(res.status, 404);
  assert.equal(res.body.code, "not_found");
});

Anti-patterns

Anti-patternWhy it bitesDo instead
Floating promise (no await/return)Unhandled rejection crashes the process (Node 15+), error detachedAwait or return every promise
Error middleware with 3 args or not lastExpress never treats it as an error handler; throws fall through4 args (err,req,res,next), registered LAST
Reading process.env.X everywhereMissing var fails at 3am, contract is invisibleValidate once in config/env.ts, export typed config
listen() inside app.tsSide effect on import; tests bind a port / double-listenapp.ts returns app, server.ts listens
catch (e) {} then continueSwallows the failure, masks the bugRe-throw, or map to an AppError
process.exit() without drainingDrops in-flight requests on deploySIGTERM → server.close() → abort → exit
Global unhandledRejection as control flowHides bugs, leaves process in a bad stateLog + exit there; fix the floating promise
Assuming Express 4 defaultsv5: urlencoded extended:false, static dotfiles:"ignore"Read references/express5-migration.md
Leaking stack/message in prodInformation disclosureStack only when NODE_ENV !== "production"

Verify

scripts/verify.sh statically lints a produced repo for these rules (4-arg error handler last, no listen() in app.ts, engines.node supported, floating-promise heuristic). Advisory; hard-fails only on listen() in app.ts or a missing error handler.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/nodejs of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/express5-migration.md
  • references/graceful-shutdown.md
  • scripts/verify.sh

Open the folder on GitHubat commit e3d5b33

Compare with similar skills

Nodejs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nodejs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nodejs this skillericrisco/rsc-harness167—~3.2kAutomated safety check: PassMIT
Fishjam JS Server SDKsoftware-mansion-labs/skills291—~1.4kAutomated safety check: PassMIT
Typescript Security Reviewgiuseppe-trisciuoglio/developer-kit355—~2.4kAutomated safety check: NotesMIT
Node Backend Development Guidelinesdiet103/claude-code-infrastructure-showcase10k2 repos~2kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works15818 repos~4kAutomated safety check: PassAGPL-3.0
Twenty Syncable Entity Validationtwentyhq/twenty58k—~3.3kAutomated safety check: PassCustom licence

Similar skills

  • Fishjam JS Server SDK

    software-mansion-labs/skills

    Node.js / TypeScript server SDK for Fishjam — backends that create rooms, mint peer tokens, listen to server notifications, and run agents.

    291 GitHub stars~1.4k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • Typescript Security Review

    giuseppe-trisciuoglio/developer-kit

    Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure.

    355 GitHub stars~2.4k tokensUpdated 27 days ago
    SecurityAuto-check: notes
  • Node Backend Development Guidelines

    diet103/claude-code-infrastructure-showcase

    Sets layered architecture and coding rules for Node.js, Express and TypeScript microservices, covering routes, controllers, services, repositories, Prisma, Sentry and Zod.

    10k GitHub starsUsed in 2 repos~2k tokens
    Backend & APIsAuto-check passed
  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    158 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed
  • Contributor guide for step three of adding a syncable entity to the Twenty server: write the validator, the migration action builder and the orchestrator wiring.

    58k GitHub stars~3.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Backend Patterns

    hellangleZ/burn-in-cceverywhere-ralph

    Backend architecture patterns, API design, database optimization, and server-side best practices for Node.js, Express, and Next.js API routes.

    112 GitHub starsUsed in 17 repos~3.3k tokens
    Backend & APIsAuto-check passed

More from ericrisco/rsc-harness

All 227 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    167 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    167 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    167 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    167 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    167 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    167 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Categories

Questions about Nodejs

What does Nodejs do?

A skill your agent uses when building or operating a plain Node.js / Express 5 backend service: project layout, async correctness, central error middleware, fail-fast config, graceful shutdown on…. Nodejs is an agent skill from ericrisco/rsc-harness.js / Express 5 backend service: project layout, async correctness, central error middleware, fail-fast config, graceful shutdown on SIGTERM.

When should I use Nodejs?

Nodejs fits situations like: operating a plain Node.js / Express 5 backend service: project layout; async correctness; central error middleware; fail-fast config.

How do I install Nodejs in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill nodejs -a claude-code`. Or copy the skill folder (skills/nodejs in ericrisco/rsc-harness) into .claude/skills/nodejs in your project. Claude Code loads it when a task matches its description.

How do I install Nodejs in Codex?

Run `npx skills add ericrisco/rsc-harness --skill nodejs -a codex`. Or copy the skill folder (skills/nodejs in ericrisco/rsc-harness) into .agents/skills/nodejs in your project. Codex loads it when a task matches its description.

Can I use Nodejs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill nodejs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nodejs, .gemini/skills/nodejs, .github/skills/nodejs and .opencode/skills/nodejs in your project.

What does Nodejs need to run?

Going by SKILL.md and its folder, Nodejs needs a shell for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js; A Bash shell; Docker.

Does Nodejs access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nodejs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Nodejs use?

Nodejs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nodejs use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Nodejs?

Skills that share tags, products or a category with Nodejs: Fishjam JS Server SDK (software-mansion-labs/skills, 291 stars), Typescript Security Review (giuseppe-trisciuoglio/developer-kit, 355 stars), Node Backend Development Guidelines (diet103/claude-code-infrastructure-showcase, 10k stars) and Nodejs Backend Patterns (ever-works/ever-works, 158 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nodejs?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 167 GitHub stars. The repository holds 227 skills in this directory. The repository was last updated on October 7, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.