Agent skill

Nestjs Security Isolation

by HoangNguyen0403 in HoangNguyen0403/agent-skills-standard

Enforce multi-tenant isolation and PostgreSQL Row Level Security in NestJS.

MITAuto-check passedBackend & APIs

Install Nestjs Security Isolation

skills CLI
$ npx skills add HoangNguyen0403/agent-skills-standard --skill nestjs-security-isolation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HoangNguyen0403/agent-skills-standard nestjs-security-isolation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HoangNguyen0403/agent-skills-standard.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/nestjs/nestjs-security-isolation .claude/skills/nestjs-security-isolation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nestjs-security-isolation
GitHub stars
572
Token cost
~547 tokens
SKILL.md length
208 words
Files
5 (incl. references)
Skills in repo
211
Repo updated
First seen
Licence
MIT

At a glance

Enforce multi-tenant isolation and PostgreSQL Row Level Security in NestJS.

  • Works in 4 steps: Migration: Create tables with ENABLE ROW… → Entity Logic: Add @Security JSDoc to… → Security Doc: Update SECURITY.md with… → …
  • Enforcing tenant isolation
  • SKILL.md covers Priority: P0 (CRITICAL), RLS Enforcement Workflow, Core Guidelines and Anti-Patterns, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Nestjs Security Isolation is an agent skill from HoangNguyen0403/agent-skills-standard. Enforce multi-tenant isolation and PostgreSQL Row Level Security in NestJS. Use when enforcing tenant isolation or PostgreSQL RLS in NestJS multi-tenant apps.

Its SKILL.md is about 550 tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including reference files (for example `evals/evals.json`, `references/auth-logic.md` and `references/implementation-patterns.md`).

It sits in Backend & APIs, covering Multi-tenancy. It works with NestJS and PostgreSQL. The repository describes itself as: A collection of Agent Skills Standard and Best Practice for Programming Languages, Frameworks that help our AI Agent follow best practies on frameworks and programming laguages. The licence is MIT.

When your agent uses it

  • Enforcing tenant isolation
  • PostgreSQL RLS in NestJS multi-tenant apps

Example prompts

  • “/nestjs-security-isolation”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Migration: Create tables with ENABLE ROW LEVEL SECURITY. Define policies using current_setting('app.current_user_id').
  2. Entity Logic: Add @Security JSDoc to entity class.
  3. Security Doc: Update SECURITY.md with new table and its access logic.
  4. Service Validation: Call childrenService.validateChildAccess(childId, userId) before any persistence operation.

What it can do on your machine

Read from SKILL.md and the folder at commit b529c2d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nestjs Security Isolation loads about 547 tokens when it runs, and up to ~1.3k if it reads all its reference files. Until then it costs about 46 tokens; SKILL.md has 208 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~547
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HoangNguyen0403/agent-skills-standard at commit b529c2d, republished under its MIT licence (© HoangNguyen0403). 208 words, ~547 tokens.

Download SKILL.mdSave it as .claude/skills/nestjs-security-isolation/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
nestjs-security-isolation
description
Enforce multi-tenant isolation and PostgreSQL Row Level Security in NestJS. Use when enforcing tenant isolation or PostgreSQL RLS in NestJS multi-tenant apps.

Priority: P0 (CRITICAL)

Strict multi-tenant isolation. All child-centric data must secured via PostgreSQL RLS and service-level validation.

RLS Enforcement Workflow

  1. Migration: Create tables with ENABLE ROW LEVEL SECURITY. Define policies using current_setting('app.current_user_id').
  2. Entity Logic: Add @Security JSDoc to entity class.
  3. Security Doc: Update SECURITY.md with new table and its access logic.
  4. Service Validation: Call childrenService.validateChildAccess(childId, userId) before any persistence operation.

Core Guidelines

  1. Mandatory RLS: Every new table linking to child or family MUST RLS enabled in its creation migration.
  2. Centralized Validation: Never reimplement access logic. Use ChildrenService for child/family membership checks.
  3. Traceable Security: SECURITY.md source of truth. Any change to RLS policies must reflected there immediately.
  4. Nested Route Constraint: Data isolation enforced at controller level via nested routes: /children/:childId/....
  5. No Direct Entity exposure: Use Response DTOs to prevent leaking internal database IDs or metadata that could circumvent security checks.

Anti-Patterns

  • No Public Tables: Don't create child-linked tables without RLS.
  • No Manual Policy Checks: Don't write raw SQL access checks in services. Use centralized validator.
  • No Stale Docs: Don't merge RLS changes without updating SECURITY.md and entity JSDoc.
  • No Root IDs: Don't use /domain/:id for child data. Always scope by :childId.

References

© HoangNguyen0403, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/nestjs/nestjs-security-isolation of HoangNguyen0403/agent-skills-standard.

  • SKILL.md
  • evals/evals.json
  • references/auth-logic.md
  • references/implementation-patterns.md
  • references/rls-patterns.md

Open the folder on GitHubat commit b529c2d

Compare with similar skills

Nestjs Security Isolation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nestjs Security Isolation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nestjs Security Isolation this skillHoangNguyen0403/agent-skills-standard572—~547Automated safety check: PassMIT
Backend Dev Guidelineslitefuse/litefuse1011 repos~5.8kAutomated safety check: PassCustom licence
Backend AI Guidelablup/backend.ai-webui1331 repos~1.8kAutomated safety check: PassLGPL-3.0
Stash Zerokmscipherstash/stack157—~4.4kAutomated safety check: PassMIT
SaaS Multi Tenantdavila7/claude-code-templates33k3 repos~3.1kAutomated safety check: PassMIT
Aurora Dsqlaws/agent-toolkit-for-aws2.8k—~9.6kAutomated safety check: PassApache-2.0

Similar skills

  • Backend Dev Guidelines

    litefuse/litefuse

    Comprehensive backend development guide for Litefuse's Next.js 14/tRPC/Express/TypeScript monorepo.

    101 GitHub starsUsed in 1 repo~5.8k tokens
    Backend & APIsAuto-check passed
  • Backend AI Guide

    lablup/backend.ai-webui

    Expert guide for Backend.AI distributed computing platform. An agent skill from lablup/backend.ai-webui.

    133 GitHub starsUsed in 1 repo~1.8k tokens
    Backend & APIsAuto-check passed
  • Stash Zerokms

    cipherstash/stack

    The ZeroKMS key model — keysets, clients, client keys, and the grant/revoke lifecycle.

    157 GitHub stars~4.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • SaaS Multi Tenant

    davila7/claude-code-templates

    Design and implement multi-tenant SaaS architectures with row-level security, tenant-scoped queries, shared-schema isolation, and safe cross-tenant admin patterns in PostgreSQL and TypeScript.

    33k GitHub starsUsed in 3 repos~3.1k tokens
    Backend & APIsAuto-check passed
  • Aurora Dsql

    aws/agent-toolkit-for-aws

    Official

    Provisions and manages Aurora DSQL clusters, connects via psql or DSQL Connectors, manages schemas, runs queries, migrates from MySQL, diagnoses query plans, and develops apps on serverless…

    2.8k GitHub stars~9.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Better Auth

    giuseppe-trisciuoglio/developer-kit

    Provides Better Auth integration patterns for NestJS backend and Next.js frontend with Drizzle ORM and PostgreSQL.

    357 GitHub stars~2.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes

More from HoangNguyen0403/agent-skills-standard

All 211 skills in this repo
  • Subagent-Driven Development

    HoangNguyen0403/agent-skills-standard

    Runs a multi-task implementation plan by sending each task to a fresh implementer subagent, reviewing it independently, then reviewing the whole branch.

    572 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • draw.io Architecture Diagramming

    HoangNguyen0403/agent-skills-standard

    Draws architecture diagrams as editable draw.io files from a JSON spec, with a fixed house style, one C4 level per diagram and evidence-tagged shapes.

    572 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Android Navigation 3 Guide

    HoangNguyen0403/agent-skills-standard

    Implements and migrates to Jetpack Navigation 3 in Compose: NavDisplay, typed route objects, a state-list back stack, deep links, multiple back stacks and dialog scenes.

    572 GitHub stars~687 tokensUpdated yesterday
    Auto-check passed
  • Angular HttpClient Standards

    HoangNguyen0403/agent-skills-standard

    Sets rules for Angular HTTP code: functional interceptors, typed requests, services that own every call, and httpResource for reactive data loading in Angular 17+.

    572 GitHub stars~652 tokensUpdated yesterday
    Auto-check passed
  • Angular Tooling

    HoangNguyen0403/agent-skills-standard

    Angular CLI usage, code generation, build configuration, and bundle optimization.

    572 GitHub stars~743 tokensUpdated yesterday
    Auto-check passed
  • Common Code Review

    HoangNguyen0403/agent-skills-standard

    Conduct high-quality, persona-driven code reviews. An agent skill from HoangNguyen0403/agent-skills-standard.

    572 GitHub stars~772 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Nestjs Security Isolation

What does Nestjs Security Isolation do?

Enforce multi-tenant isolation and PostgreSQL Row Level Security in NestJS. Nestjs Security Isolation is an agent skill from HoangNguyen0403/agent-skills-standard. Enforce multi-tenant isolation and PostgreSQL Row Level Security in NestJS.

When should I use Nestjs Security Isolation?

Nestjs Security Isolation fits situations like: enforcing tenant isolation; postgreSQL RLS in NestJS multi-tenant apps.

How do I install Nestjs Security Isolation in Claude Code?

Run `npx skills add HoangNguyen0403/agent-skills-standard --skill nestjs-security-isolation -a claude-code`. Or copy the skill folder (skills/nestjs/nestjs-security-isolation in HoangNguyen0403/agent-skills-standard) into .claude/skills/nestjs-security-isolation in your project. Claude Code loads it when a task matches its description.

How do I install Nestjs Security Isolation in Codex?

Run `npx skills add HoangNguyen0403/agent-skills-standard --skill nestjs-security-isolation -a codex`. Or copy the skill folder (skills/nestjs/nestjs-security-isolation in HoangNguyen0403/agent-skills-standard) into .agents/skills/nestjs-security-isolation in your project. Codex loads it when a task matches its description.

Can I use Nestjs Security Isolation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HoangNguyen0403/agent-skills-standard --skill nestjs-security-isolation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nestjs-security-isolation, .gemini/skills/nestjs-security-isolation, .github/skills/nestjs-security-isolation and .opencode/skills/nestjs-security-isolation in your project.

What does Nestjs Security Isolation need to run?

SKILL.md names no scripts, command-line tools or credentials: Nestjs Security Isolation is instructions for the agent only.

Does Nestjs Security Isolation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Nestjs Security Isolation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nestjs Security Isolation use?

Nestjs Security Isolation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nestjs Security Isolation use?

About 547 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 765 tokens, read only when the agent opens those files.

What are the alternatives to Nestjs Security Isolation?

Skills that share tags, products or a category with Nestjs Security Isolation: Backend Dev Guidelines (litefuse/litefuse, 101 stars), Backend AI Guide (lablup/backend.ai-webui, 133 stars), Stash Zerokms (cipherstash/stack, 157 stars) and SaaS Multi Tenant (davila7/claude-code-templates, 33k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nestjs Security Isolation?

HoangNguyen0403 (a GitHub user) maintains it in HoangNguyen0403/agent-skills-standard, which has 572 GitHub stars. The repository holds 211 skills in this directory. The repository was last updated on October 9, 2026.

Source: HoangNguyen0403/agent-skills-standard on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.