Provides comprehensive code review capability for NestJS applications, analyzing controllers, services, modules, guards, interceptors, pipes, dependency injection, and database integration patterns.

MITAuto-check: notesDevelopment

Install Nestjs Code Review

skills CLI
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill nestjs-code-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install giuseppe-trisciuoglio/developer-kit nestjs-code-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/nestjs-code-review .claude/skills/nestjs-code-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nestjs-code-review
GitHub stars
357
Token cost
~2.3k tokens
SKILL.md length
632 words
Files
4 (incl. references)
Skills in repo
115
Repo updated
First seen
Licence
MIT

At a glance

Provides comprehensive code review capability for NestJS applications, analyzing controllers, services, modules, guards, interceptors, pipes, dependency injection, and database integration patterns.

  • Works in 6 steps: Summary → Critical Issues (Must Fix) → Warnings (Should Fix) → …
  • Reviewing NestJS code changes
  • SKILL.md covers Overview, When to Use, Instructions and Examples, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nestjs Code Review is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides comprehensive code review capability for NestJS applications, analyzing controllers, services, modules, guards, interceptors, pipes, dependency injection, and database integration patterns. Use when reviewing NestJS code changes, before merging pull requests, after implementing new features, or for architecture validation. Triggers on "review NestJS code", "NestJS code review", "check my NestJS controller/service".

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/anti-patterns.md`, `references/checklist.md` and `references/patterns.md`).

It sits in Development, covering Code review, Design patterns and Pull requests. It works with NestJS. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.

When your agent uses it

  • Reviewing NestJS code changes
  • Before merging pull requests
  • After implementing new features
  • For architecture validation

Example prompts

  • “review NestJS code”
  • “NestJS code review”
  • “check my NestJS controller/service”
  • “/nestjs-code-review”

Requirements

  • Pre-approved tools (allowed-tools): Read, Edit, Grep, Glob, Bash

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Summary
  2. Critical Issues (Must Fix)
  3. Warnings (Should Fix)
  4. Suggestions (Consider Improving)
  5. Positive Observations
  6. Recommendations

What it can do on your machine

Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Edit
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nestjs Code Review loads about 2.3k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 632 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Edit, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 632 words, ~2,267 tokens.

Download SKILL.mdSave it as .claude/skills/nestjs-code-review/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
nestjs-code-review
description
Provides comprehensive code review capability for NestJS applications, analyzing controllers, services, modules, guards, interceptors, pipes, dependency injection, and database integration patterns. Use when reviewing NestJS code changes, before merging pull requests, after implementing new features, or for architecture validation. Triggers on "review NestJS code", "NestJS code review", "check my NestJS controller/service".
allowed-tools
Read, Edit, Grep, Glob, Bash

NestJS Code Review

Overview

Provides structured code review for NestJS applications. Findings categorized by severity (Critical, Warning, Suggestion) with actionable recommendations. Delegates to nestjs-code-review-expert agent for deep analysis.

When to Use

  • "review NestJS code", "NestJS code review", "check my NestJS controller/service"
  • Before merging pull requests or after implementing new features
  • Validating NestJS decorators, DI patterns, guard implementations
  • Architecture validation for NestJS modules and providers
  • Reviewing DTOs, pipes, interceptors, and database integration (TypeORM, Prisma, Drizzle)

Instructions

  1. Identify Scope: Determine which NestJS files and modules are under review. Use glob and grep to discover controllers, services, modules, guards, interceptors, and pipes in the target area.

  2. Analyze Module Structure: Verify proper module organization — each feature should have its own module with clearly defined imports, controllers, providers, and exports. Check for circular dependencies and proper module boundaries.

  3. Review Dependency Injection: Validate that all injectable services use constructor injection. Check provider scoping (singleton, request, transient) matches the intended lifecycle. Ensure no direct instantiation bypasses the DI container.

  4. Evaluate Controllers: Review HTTP method usage, route naming, status codes, request/response DTOs, validation pipes, and OpenAPI decorators. Confirm controllers are thin — business logic belongs in services.

  5. Assess Services & Business Logic: Check that services encapsulate business logic properly. Verify error handling, transaction management, and proper separation from infrastructure concerns. Look for service methods that are too large or have too many responsibilities.

  6. Check Security: Review guard implementations, authentication/authorization patterns, input validation with class-validator, and protection against common vulnerabilities (injection, XSS, CSRF).

  7. Review Testing: Assess test coverage for controllers, services, guards, and pipes. Verify proper mocking strategies and that tests validate behavior, not implementation details.

  8. Validate Findings (Required checkpoint): Before finalizing, verify each Critical and Warning finding has reproducible evidence (file path, line numbers, exact code snippet) and a concrete, actionable fix. Remove or downgrade findings that are style preferences, overly subjective, or lack concrete remediation.

  9. Produce Review Report: Generate structured report with severity-classified findings (Critical, Warning, Suggestion), positive observations, and prioritized recommendations with code examples.

Examples

Example 1: Reviewing a Controller
typescript
// ❌ Bad: Fat controller with business logic and missing validation
@Controller('users')
export class UserController {
  constructor(private readonly userRepo: Repository<User>) {}

  @Post()
  async create(@Body() body: any) {
    const user = this.userRepo.create(body);
    return this.userRepo.save(user);
  }
}

// ✅ Good: Thin controller with proper DTOs, validation, and service delegation
@Controller('users')
@ApiTags('Users')
export class UserController {
  constructor(private readonly userService: UserService) {}

  @Post()
  @HttpCode(HttpStatus.CREATED)
  @ApiOperation({ summary: 'Create a new user' })
  @ApiResponse({ status: 201, type: UserResponseDto })
  async create(
    @Body(ValidationPipe) createUserDto: CreateUserDto,
  ): Promise<UserResponseDto> {
    return this.userService.create(createUserDto);
  }
}
Example 2: Reviewing Dependency Injection
typescript
// ❌ Bad: Direct instantiation bypasses DI
@Injectable()
export class OrderService {
  private readonly logger = new Logger();
  private readonly emailService = new EmailService();

  async createOrder(dto: CreateOrderDto) {
    this.emailService.send(dto.email, 'Order created');
  }
}

// ✅ Good: Proper constructor injection
@Injectable()
export class OrderService {
  private readonly logger = new Logger(OrderService.name);

  constructor(
    private readonly orderRepository: OrderRepository,
    private readonly emailService: EmailService,
  ) {}

  async createOrder(dto: CreateOrderDto): Promise<Order> {
    const order = await this.orderRepository.create(dto);
    await this.emailService.send(dto.email, 'Order created');
    return order;
  }
}
Example 3: Reviewing Error Handling
typescript
// ❌ Bad: Generic error handling with information leakage
@Get(':id')
async findOne(@Param('id') id: string) {
  try {
    return await this.service.findOne(id);
  } catch (error) {
    throw new HttpException(error.message, 500);
  }
}

// ✅ Good: Domain-specific exceptions with proper HTTP mapping
@Get(':id')
async findOne(@Param('id', ParseUUIDPipe) id: string): Promise<UserResponseDto> {
  const user = await this.userService.findOne(id);
  if (!user) {
    throw new NotFoundException(`User with ID ${id} not found`);
  }
  return user;
}
Example 4: Reviewing Guard Implementation
typescript
// ❌ Bad: Authorization logic in controller
@Get('admin/dashboard')
async getDashboard(@Req() req: Request) {
  if (req.user.role !== 'admin') {
    throw new ForbiddenException();
  }
  return this.dashboardService.getData();
}

// ✅ Good: Guard-based authorization with decorator
@Get('admin/dashboard')
@UseGuards(JwtAuthGuard, RolesGuard)
@Roles(Role.ADMIN)
async getDashboard(): Promise<DashboardDto> {
  return this.dashboardService.getData();
}
Example 5: Reviewing Module Organization
typescript
// ❌ Bad: Monolithic module with everything
@Module({
  imports: [TypeOrmModule.forFeature([User, Order, Product, Review])],
  controllers: [UserController, OrderController, ProductController],
  providers: [UserService, OrderService, ProductService, ReviewService],
})
export class AppModule {}

// ✅ Good: Feature-based module organization
@Module({
  imports: [UserModule, OrderModule, ProductModule],
})
export class AppModule {}

@Module({
  imports: [TypeOrmModule.forFeature([User])],
  controllers: [UserController],
  providers: [UserService, UserRepository],
  exports: [UserService],
})
export class UserModule {}

Review Output Format

Structure all code review findings as follows:

1. Summary

Brief overview with an overall quality score (1-10) and key observations.

Show full SKILL.md (248 more words)Show less
2. Critical Issues (Must Fix)

Issues that could cause security vulnerabilities, data corruption, or production failures.

3. Warnings (Should Fix)

Issues that violate best practices, reduce maintainability, or could lead to bugs.

4. Suggestions (Consider Improving)

Improvements for code readability, performance, or developer experience.

5. Positive Observations

Well-implemented patterns and good practices to acknowledge and encourage.

6. Recommendations

Prioritized next steps with code examples for the most impactful improvements.

Best Practices

  • Controllers should be thin — delegate all business logic to services
  • Use DTOs with class-validator for all request/response payloads
  • Apply ParseUUIDPipe, ParseIntPipe, etc. for parameter validation
  • Use domain-specific exception classes extending HttpException
  • Organize code into feature modules with clear boundaries and exports
  • Prefer constructor injection — never use new for injectable services
  • Apply guards for authentication and authorization, not inline checks
  • Use interceptors for cross-cutting concerns (logging, caching, transformation)
  • Add OpenAPI decorators (@ApiTags, @ApiOperation, @ApiResponse) to all endpoints
  • Write unit tests for services and integration tests for controllers

Constraints and Warnings

  • Do not enforce a single ORM — the codebase may use TypeORM, Prisma, Drizzle, or MikroORM
  • Respect existing project conventions even if they differ from NestJS defaults
  • Focus on high-confidence issues — avoid false positives on style preferences
  • When reviewing microservices patterns, consider transport-layer specific constraints
  • Do not suggest architectural rewrites unless critical issues warrant them

References

See the references/ directory for detailed review checklists and pattern documentation:

  • references/patterns.md — NestJS best practice patterns with examples
  • references/anti-patterns.md — Common NestJS anti-patterns to flag during review
  • references/checklist.md — Comprehensive review checklist organized by area

© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in plugins/developer-kit-typescript/skills/nestjs-code-review of giuseppe-trisciuoglio/developer-kit.

  • SKILL.md
  • references/anti-patterns.md
  • references/checklist.md
  • references/patterns.md

Open the folder on GitHubat commit fe73fb3

Compare with similar skills

Nestjs Code Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nestjs Code Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nestjs Code Review this skillgiuseppe-trisciuoglio/developer-kit357—~2.3kAutomated safety check: NotesMIT
Code Review SkillRain-kl/OpenFlare289—~2.3kAutomated safety check: NotesMIT
Reviewing Changesbitwarden/ios699—~1.1kAutomated safety check: PassGPL-3.0
Nestjs Git Commit PR Messageaiskillstore/marketplace433—~2.4kAutomated safety check: PassMIT
Feature Devsecondsky/claude-skills227—~2.4kAutomated safety check: NotesMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Code Review Skill

    Rain-kl/OpenFlare

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, PHP, Python, Django, Go, C/.NET, Kotlin, Swift, NestJS, C/C++, and more.

    289 GitHub stars~2.3k tokensUpdated 3 days ago
    DevelopmentAuto-check: notes
  • Reviewing Changes

    bitwarden/ios

    Official

    Performs comprehensive code reviews for Bitwarden iOS projects, verifying architecture compliance, style guidelines, compilation safety, test coverage, and security requirements.

    699 GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Nestjs Git Commit PR Message

    aiskillstore/marketplace

    Prepares and publishes intentional Git changes for NestJS projects.

    433 GitHub stars~2.4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Feature Dev

    secondsky/claude-skills

    Automate 7-phase feature development with specialized agents (code-explorer, code-architect, code-reviewer).

    227 GitHub stars~2.4k tokensUpdated 13 days ago
    DevelopmentAuto-check: notes
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from giuseppe-trisciuoglio/developer-kit

All 115 skills in this repo
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    357 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Actuator

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

    357 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Crud Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides and generates complete CRUD workflows for Spring Boot 3 services.

    357 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    357 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • PR Review Comments

    giuseppe-trisciuoglio/developer-kit

    Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

    357 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check: notes

Works with

Questions about Nestjs Code Review

What does Nestjs Code Review do?

Provides comprehensive code review capability for NestJS applications, analyzing controllers, services, modules, guards, interceptors, pipes, dependency injection, and database integration patterns. Nestjs Code Review is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides comprehensive code review capability for NestJS applications, analyzing controllers, services, modules, guards, interceptors, pipes, dependency injection, and database integration patterns.

When should I use Nestjs Code Review?

Nestjs Code Review fits situations like: reviewing NestJS code changes; before merging pull requests; after implementing new features; for architecture validation.

How do I install Nestjs Code Review in Claude Code?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill nestjs-code-review -a claude-code`. Or copy the skill folder (plugins/developer-kit-typescript/skills/nestjs-code-review in giuseppe-trisciuoglio/developer-kit) into .claude/skills/nestjs-code-review in your project. Claude Code loads it when a task matches its description.

How do I install Nestjs Code Review in Codex?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill nestjs-code-review -a codex`. Or copy the skill folder (plugins/developer-kit-typescript/skills/nestjs-code-review in giuseppe-trisciuoglio/developer-kit) into .agents/skills/nestjs-code-review in your project. Codex loads it when a task matches its description.

Can I use Nestjs Code Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill nestjs-code-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nestjs-code-review, .gemini/skills/nestjs-code-review, .github/skills/nestjs-code-review and .opencode/skills/nestjs-code-review in your project.

What does Nestjs Code Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Nestjs Code Review is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Edit, Grep, Glob, Bash.

Does Nestjs Code Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nestjs Code Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Nestjs Code Review use?

Nestjs Code Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nestjs Code Review use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.6k tokens, read only when the agent opens those files.

What are the alternatives to Nestjs Code Review?

Skills that share tags, products or a category with Nestjs Code Review: Code Review Skill (Rain-kl/OpenFlare, 289 stars), Reviewing Changes (bitwarden/ios, 699 stars), Nestjs Git Commit PR Message (aiskillstore/marketplace, 433 stars) and Feature Dev (secondsky/claude-skills, 227 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nestjs Code Review?

giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.

Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.