Node.js backend runtime and process-lifecycle rules that Claude reliably gets wrong.

MITAuto-check passedDevOps & Cloud

Install Nodejs

skills CLI
$ npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nodejs -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install TheDecipherist/claude-code-mastery-project-starter-kit nodejs --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/TheDecipherist/claude-code-mastery-project-starter-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/nodejs .claude/skills/nodejs && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
nodejs
GitHub stars
338
Token cost
~1.7k tokens
SKILL.md length
649 words
Files
1
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

Node.js backend runtime and process-lifecycle rules that Claude reliably gets wrong.

  • Writing a Node server
  • SKILL.md covers Graceful shutdown, done…, Let it crash, never swallow a…, Don't block the event loop and Load instrumentation before…, plus 3 more sections
  • Calls docker
  • Long-running script

What it does

Nodejs is an agent skill from TheDecipherist/claude-code-mastery-project-starter-kit. Node.js backend runtime and process-lifecycle rules that Claude reliably gets wrong. Use when writing a Node server or long-running script, an Express app, worker threads, or process signal handling, and when choosing packages. Covers correct graceful shutdown, crash-on-fault instead of swallowing errors, not blocking the event loop, loading instrumentation first, securing the session cookie, and replacing deprecated packages with built-ins. Defers MongoDB to mongodb-rules, schema/validation to…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Async programming, NoSQL databases and Containers. It works with Node.js, Docker and MongoDB. The repository describes itself as: The definitive starting point for Claude Code projects. Based on Claude Code Mastery Guides V1-V5. The licence is MIT.

When your agent uses it

  • Writing a Node server
  • Long-running script
  • Process signal handling
  • When choosing packages

Example prompts

  • “/nodejs”

Requirements

  • Node.js
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 61fbb99. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • docker

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use docker, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Nodejs loads about 1.7k tokens when it runs. Until then it costs about 144 tokens; SKILL.md has 649 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from TheDecipherist/claude-code-mastery-project-starter-kit at commit 61fbb99, republished under its MIT licence (© TheDecipherist). 649 words, ~1,734 tokens.

Download SKILL.mdSave it as .claude/skills/nodejs/SKILL.md (or your agent's skills folder).
name
nodejs
description
Node.js backend runtime and process-lifecycle rules that Claude reliably gets wrong. Use when writing a Node server or long-running script, an Express app, worker threads, or process signal handling, and when choosing packages. Covers correct graceful shutdown, crash-on-fault instead of swallowing errors, not blocking the event loop, loading instrumentation first, securing the session cookie, and replacing deprecated packages with built-ins. Defers MongoDB to mongodb-rules, schema/validation to schema-source-of-truth, and image/deploy to docker and docker-swarm.
when_to_use
- Writing a Node server (`server.js`, Express) or a long-running script or worker - Adding or reviewing process signal handling, graceful shutdown, or error…

Node.js: Process Lifecycle and Runtime Rules

Claude writes Node services that work in a demo and fall over in production, almost always around the process lifecycle. These are the parts to get right.

Graceful shutdown, done correctly

A server must shut down cleanly on SIGTERM (what docker stop, Swarm, and Kubernetes send) and SIGINT (Ctrl-C). Claude usually omits this entirely, so the orchestrator waits the grace period and then SIGKILLs, dropping in-flight requests. The correct sequence is: stop accepting new connections, drain in-flight ones, close dependencies, exit 0, with a hard timeout so a stuck connection can't block shutdown forever.

javascript
const server = app.listen(port);
let shuttingDown = false;

async function shutdown(signal) {
  if (shuttingDown) return;                 // ignore repeat signals
  shuttingDown = true;
  logger.info("shutting down", { signal });

  const force = setTimeout(() => {           // drain hung? force it
    logger.error("shutdown timed out, forcing exit");
    process.exit(1);
  }, 10_000);
  force.unref();

  try {
    await new Promise((r) => server.close(r)); // stop new conns, let in-flight finish
    await db.close();                          // then close DB, redis, change streams
    clearTimeout(force);
    process.exit(0);
  } catch (err) {
    logger.error("error during shutdown", { err });
    process.exit(1);
  }
}

process.on("SIGTERM", () => shutdown("SIGTERM"));
process.on("SIGINT",  () => shutdown("SIGINT"));

Two things that look fine but are bugs: do not put async cleanup in a process.on("exit", ...) handler, the event loop is already stopped so nothing async runs, exit is for synchronous work only. And do not trap SIGUSR1, Node uses it for the debugger. This only works if the process actually receives the signal, which means an exec-form ENTRYPOINT so Node is PID 1 (see the docker skill) and init: true so signals are forwarded (see docker-swarm).

Let it crash, never swallow a fault

On uncaughtException or unhandledRejection the process is in an unknown, possibly corrupt state. Log it and exit non-zero, let the orchestrator restart a clean process. Do not catch-and-continue. Modern Node already terminates on an unhandled rejection by default, so code that relies on swallowing one is both wrong and fragile.

javascript
process.on("uncaughtException", (err) => {
  logger.error("uncaught exception", { err });
  process.exit(1);            // exit non-zero so restart_policy: on-failure restarts
});
process.on("unhandledRejection", (reason) => {
  logger.error("unhandled rejection", { reason });
  process.exit(1);
});

The non-zero exit is what makes Swarm/K8s self-healing fire, an exit(0) on a crash reads as success and the dead service is never restarted (see docker-swarm). You can route these through shutdown() to drain first, but never let the process keep serving after one.

Don't block the event loop

Node runs your JavaScript on a single thread. A CPU-bound stretch, parsing a huge payload, hashing, image work, a tight loop over a large array, freezes every concurrent request until it finishes. I/O is already async and is not the problem. For real CPU work, offload to worker_threads, not child_process (for in-process JS) and not "just make it async" (await doesn't yield during a synchronous loop).

javascript
const { Worker } = require("node:worker_threads");
new Worker("./workers/process.js", {
  workerData,
  resourceLimits: { maxOldGenerationSizeMb: 512 },  // cap so one worker can't OOM the host
});

Load instrumentation before anything else

APM and tracing libraries (dd-trace, the OpenTelemetry SDK) work by monkey-patching http, express, and your DB driver. They can only patch modules loaded after them, so the init call must be the very first thing in the entry file, before any require("express"). Required late, it silently instruments nothing.

javascript
// server.js, line 1
require("dd-trace").init({ /* ... */ });
const express = require("express");   // now traced
Show full SKILL.md (247 more words)Show less

When Claude sets up sessions it usually sets httpOnly and stops. Set all three: httpOnly (no JS access), secure in production (HTTPS only), and sameSite (CSRF defense), which is the one that gets missed.

javascript
cookie: { httpOnly: true, secure: isProd, sameSite: "lax", maxAge: 86_400_000 }

Related CORS gotcha: credentials: true cannot be combined with origin: "*", the browser rejects it. Echo a specific allowed origin instead.

Reach for built-ins, replace deprecated packages

Claude's training pulls in libraries that are now deprecated or unnecessary. Prefer the platform:

  • crypto.randomUUID() over the uuid package for a v4 id, and uuid over node-uuid
  • native fetch (Node 18+) or axios over request (unmaintained since 2020)
  • node:test + node:assert for simple suites, structuredClone() over a deep-clone dep
  • the Intl APIs or date-fns/Temporal over moment (in maintenance mode)
  • @aws-sdk/client-* v3 (modular) over the monolithic aws-sdk v2
  • sass (dart-sass) over the deprecated node-sass

Use the node: prefix on built-in imports (require("node:fs")) so there's no ambiguity with a same-named package.

Two smaller ones

  • Logging: a structured logger (pino or winston) emitting JSON to stdout in production, never console.log in a hot path. stdout because the container's logging driver collects it (see docker).
  • PM2: cluster mode is for using all cores on a VM or bare-metal host. Inside a Swarm or K8s container, run one Node process and scale with replicas plus init: true, don't stack two process managers that both try to own restarts.

This skill is built to grow. Add a rule when a real Node production failure has a stable, defensible fix.

© TheDecipherist, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/nodejs of TheDecipherist/claude-code-mastery-project-starter-kit.

Open the folder on GitHubat commit 61fbb99

Compare with similar skills

Nodejs next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Nodejs compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Nodejs this skillTheDecipherist/claude-code-mastery-project-starter-kit338—~1.7kAutomated safety check: PassMIT
Monstermq Broker Configvogler75/monster-mq142—~2.2kAutomated safety check: PassGPL-3.0
Full Stack Developertheneoai/awesome-skills183—~2.2kAutomated safety check: PassMIT
Foundationdb AspireSnowBankSDK/foundationdb-dotnet-client158—~3.4kAutomated safety check: PassBSD-3-Clause
Use Sealoshashgraph-online/awesome-codex-plugins1.2k—~2.2kAutomated safety check: PassApache-2.0
Reflexo ReleaseMyriad-Dreamin/typst.ts1.2k—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Monstermq Broker Config

    vogler75/monster-mq

    Guide for configuring, deploying, and operating the MonsterMQ broker.

    142 GitHub stars~2.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Full Stack Developer

    theneoai/awesome-skills

    Elite Full-Stack Developer skill with mastery of modern frontend frameworks (React, Vue, TypeScript), backend systems (Node.js, Python, Go), databases (PostgreSQL, MongoDB, Redis), and DevOps…

    183 GitHub stars~2.2k tokensUpdated 4 mo ago
    DatabasesAuto-check passed
  • Foundationdb Aspire

    SnowBankSDK/foundationdb-dotnet-client

    How to run a FoundationDB cluster and connect to it from .NET — getting the IFdbDatabaseProvider that the keys/transactions/layers skills assume you already have.

    158 GitHub stars~3.4k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Use Sealos

    hashgraph-online/awesome-codex-plugins

    Deploy and operate apps on Sealos Cloud: sign in to a Sealos account, deploy any project or self-hosted app (from the template store, an official Docker image, or project source code), provision…

    1.2k GitHub stars~2.2k tokensUpdated yesterday
    DatabasesAuto-check passed
  • Reflexo Release

    Myriad-Dreamin/typst.ts

    Guide Reflexo/typst.ts release preparation and operator handoffs.

    1.2k GitHub stars~1.5k tokensUpdated 13 days ago
    DevOps & CloudAuto-check passed
  • GitHub Actions Creator

    FNOSP/FlyNarwhal

    A skill your agent uses when the user wants to create, generate, or set up a GitHub Actions workflow.

    495 GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed

More from TheDecipherist/claude-code-mastery-project-starter-kit

All 24 skills in this repo
  • Create Service

    TheDecipherist/claude-code-mastery-project-starter-kit

    Scaffold a new microservice that follows the project's server/handlers/adapters architecture.

    338 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check: notes
  • CSS Structure

    TheDecipherist/claude-code-mastery-project-starter-kit

    Where CSS should live. An agent skill from TheDecipherist/claude-code-mastery-project-starter-kit.

    338 GitHub stars~1k tokensUpdated 3 mo ago
    Auto-check passed
  • Docker

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production Docker best practices for writing Dockerfiles, Compose files, and Swarm stacks.

    338 GitHub stars~1.6k tokensUpdated 3 mo ago
    Auto-check: notes
  • Docker Swarm

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production Docker Swarm deployment rules: what changes when a compose file goes from a single node to a multi-node Swarm.

    338 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • Mongodb Backups

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production MongoDB backup and restore practices that the documentation gets wrong.

    338 GitHub stars~1.3k tokensUpdated 3 mo ago
    Auto-check passed
  • Mongodb Replica Sets

    TheDecipherist/claude-code-mastery-project-starter-kit

    Production MongoDB replica-set operation: topology, durability, host tuning, and the container-specific gotchas Claude gets wrong.

    338 GitHub stars~1.6k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Nodejs

What does Nodejs do?

Node.js backend runtime and process-lifecycle rules that Claude reliably gets wrong. Nodejs is an agent skill from TheDecipherist/claude-code-mastery-project-starter-kit.js backend runtime and process-lifecycle rules that Claude reliably gets wrong.

When should I use Nodejs?

Nodejs fits situations like: writing a Node server; long-running script; process signal handling; when choosing packages.

How do I install Nodejs in Claude Code?

Run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nodejs -a claude-code`. Or copy the skill folder (.claude/skills/nodejs in TheDecipherist/claude-code-mastery-project-starter-kit) into .claude/skills/nodejs in your project. Claude Code loads it when a task matches its description.

How do I install Nodejs in Codex?

Run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nodejs -a codex`. Or copy the skill folder (.claude/skills/nodejs in TheDecipherist/claude-code-mastery-project-starter-kit) into .agents/skills/nodejs in your project. Codex loads it when a task matches its description.

Can I use Nodejs in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add TheDecipherist/claude-code-mastery-project-starter-kit --skill nodejs -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/nodejs, .gemini/skills/nodejs, .github/skills/nodejs and .opencode/skills/nodejs in your project.

What does Nodejs need to run?

Going by SKILL.md and its folder, Nodejs needs the command-line tools its instructions call (docker). Our summary lists: Node.js; Docker.

Does Nodejs access the network?

SKILL.md contains no URLs. Its commands use docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Nodejs safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Nodejs use?

Nodejs is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Nodejs use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Nodejs?

Skills that share tags, products or a category with Nodejs: Monstermq Broker Config (vogler75/monster-mq, 142 stars), Full Stack Developer (theneoai/awesome-skills, 183 stars), Foundationdb Aspire (SnowBankSDK/foundationdb-dotnet-client, 158 stars) and Use Sealos (hashgraph-online/awesome-codex-plugins, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Nodejs?

TheDecipherist (a GitHub user) maintains it in TheDecipherist/claude-code-mastery-project-starter-kit, which has 338 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on June 29, 2026.

Source: TheDecipherist/claude-code-mastery-project-starter-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.