Agent skill

Tsed Middlewares

by tsedio in tsedio/tsed

Add cross-cutting request logic to a Ts.ED v8 application with middlewares, auth guards, interceptors and pipes.

MITAuto-check passedBackend & APIs

Install Tsed Middlewares

skills CLI
$ npx skills add tsedio/tsed --skill tsed-middlewares -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install tsedio/tsed tsed-middlewares --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/tsedio/tsed.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/tsed/skills/tsed-middlewares .claude/skills/tsed-middlewares && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tsed-middlewares
GitHub stars
3.1k
Token cost
~2.4k tokens
SKILL.md length
754 words
Files
2
Skills in repo
16
Repo updated
First seen
Licence
MIT

At a glance

Add cross-cutting request logic to a Ts.ED v8 application with middlewares, auth guards, interceptors and pipes.

  • Works in 6 steps: Write a middleware → Attach to controllers and endpoints → Register global middlewares → …
  • Writing a @Middleware class
  • SKILL.md covers 1. Write a middleware, 2. Attach to controllers and…, 3. Register global middlewares and 4. Build an auth decorator, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Tsed Middlewares is an agent skill from tsedio/tsed. Add cross-cutting request logic to a Ts.ED v8 application with middlewares, auth guards, interceptors and pipes. Use when writing a @Middleware class, registering global Express/Koa/Fastify middlewares through the middlewares configuration or $beforeRoutesInit, applying @UseBefore/@Use/@UseAfter/@UseBeforeEach, building a custom auth decorator with @UseAuth and useDecorators, wrapping service methods with @Interceptor/@Intercept, transforming a parameter with @UsePipe, caching with @UseCache, or when the error…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Backend & APIs, covering Caching. It works with Fastify. The repository describes itself as: :triangularruler: Ts.ED is a Node.js and TypeScript framework on top of Express to write your application with TypeScript (or ES6). It provides a lot of decorators and guideline… The licence is MIT.

When your agent uses it

  • Writing a @Middleware class
  • Registering global Express/Koa/Fastify middlewares through the middlewares configuration
  • $beforeRoutesInit
  • Applying @UseBefore/@Use/@UseAfter/@UseBeforeEach

Example prompts

  • “middleware cannot be added on $beforeInit hook”
  • “/tsed-middlewares”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Write a middleware
  2. Attach to controllers and endpoints
  3. Register global middlewares
  4. Build an auth decorator
  5. Write an interceptor
  6. Write a pipe

What it can do on your machine

Read from SKILL.md and the folder at commit cc5a0da. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • tsed.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tsed Middlewares loads about 2.4k tokens when it runs. Until then it costs about 148 tokens; SKILL.md has 754 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~148
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from tsedio/tsed at commit cc5a0da, republished under its MIT licence (© tsedio). 754 words, ~2,427 tokens.

Download SKILL.mdSave it as .claude/skills/tsed-middlewares/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
tsed-middlewares
description
Add cross-cutting request logic to a Ts.ED v8 application with middlewares, auth guards, interceptors and pipes. Use when writing a @Middleware class, registering global Express/Koa/Fastify middlewares through the `middlewares` configuration or $beforeRoutesInit, applying @UseBefore/@Use/@UseAfter/@UseBeforeEach, building a custom auth decorator with @UseAuth and useDecorators, wrapping service methods with @Interceptor/@Intercept, transforming a parameter with @UsePipe, caching with @UseCache, or when the error "middleware cannot be added on $beforeInit hook" appears.

Ts.ED Middlewares, Interceptors and Pipes

Pick the narrowest tool first, then implement it as an injectable class.

NeedUsePackage
Run before/after a route with access to request, response and endpoint metadata (auth, headers, tenant)Middleware@tsed/platform-middlewares
Wrap any injectable method: timing, retry, fallback, caching, transactionsInterceptor@tsed/di
Transform or validate one handler parameter (id to entity, parsing)Pipe@tsed/platform-params, @tsed/schema
React to application or request lifecycle ($onRequest, $onResponse, $onReady)Hooksee tsed-di, https://tsed.dev/docs/hooks.md
Change the shape of every response or errorResponse filter / exception filtersee tsed-exceptions

Never import from @tsed/common.

1. Write a middleware

typescript
import {Unauthorized} from "@tsed/exceptions";
import {Middleware, type MiddlewareMethods} from "@tsed/platform-middlewares";
import {Context} from "@tsed/platform-params";

@Middleware()
export class ApiKeyMiddleware implements MiddlewareMethods {
  use(@Context() $ctx: Context) {
    const options = $ctx.endpoint.get(ApiKeyMiddleware) || {};
    if ($ctx.request.get("x-api-key") !== options.key) {
      throw new Unauthorized("Invalid API key");
    }
  }
}
  1. Implement use(...). Inject what is needed with parameter decorators (@Context(), @HeaderParams(), @QueryParams()); inject services with @Inject() or inject().
  2. Finish by returning or awaiting. Do not call next(); throw an exception from @tsed/exceptions to stop the request.
  3. Read per-endpoint options with $ctx.endpoint.get(MiddlewareClass). This is only available for endpoint-level middlewares, not global ones.
  4. Use $ctx.request / $ctx.response (platform abstractions) so the code stays portable across Express, Koa and Fastify.

2. Attach to controllers and endpoints

  1. @UseBefore(M): before the handler. @Use(M): just before the handler, after @UseBefore. @UseAfter(M): after the handler when it returned no data.
  2. On a class, @UseBefore runs once for the controller; @UseBeforeEach(M) runs before each of its endpoints.
  3. All four accept Ts.ED middleware classes or raw framework functions, and come from @tsed/platform-middlewares.
  4. Call order: global middlewares, controller @UseBefore, controller @UseBeforeEach, endpoint @UseBefore, controller @Use, endpoint @Use, handler, endpoint @UseAfter, send response. Once a handler returns data the response is sent and later @UseAfter and global middlewares are skipped.
  5. Prefer an interceptor or response filter over @UseAfter for post-processing.
  6. Do not write Express error middlewares (@Err(), four-argument functions); use exception filters (tsed-exceptions).

3. Register global middlewares

typescript
import {Env} from "@tsed/core";
import {Configuration} from "@tsed/di";
import compression from "compression";
import helmet from "helmet";
import {RequestIdMiddleware} from "./middlewares/RequestIdMiddleware.js";

@Configuration({
  middlewares: [
    {use: helmet(), hook: "$afterInit"},
    "json-parser",
    {use: "urlencoded-parser", options: {extended: true}},
    {use: compression(), env: Env.PROD},
    RequestIdMiddleware
  ]
})
export class Server {}
  1. Each entry is a function, a Ts.ED middleware class, a string, or {use, hook?, env?, options?}. Default hook: $beforeRoutesInit.
  2. Built-in strings: json-parser, urlencoded-parser, text-parser, raw-parser. Any other string is imported as a module and called with options.
  3. Ts.ED middleware classes need the request context: register them on $beforeRoutesInit or later. On $beforeInit, $onInit or $afterInit only raw framework middlewares are accepted and a class throws at startup.
  4. Alternative: inject PlatformApplication from @tsed/platform-http in the server and call this.app.use(M) inside $beforeRoutesInit() or $afterRoutesInit(). Hook registrations run before the middlewares list.
  5. Raw middlewares are framework specific. Do not register an Express middleware in a Koa or Fastify application.

4. Build an auth decorator

typescript
import {useDecorators} from "@tsed/core";
import {UseAuth} from "@tsed/platform-middlewares";
import {In, Returns, Security} from "@tsed/schema";
import {AuthMiddleware} from "../middlewares/AuthMiddleware.js";

export function Auth(options: {role?: string; scopes?: string[]} = {}): Function {
  return useDecorators(
    UseAuth(AuthMiddleware, options),
    Security("oauth", ...(options.scopes || [])),
    In("header").Name("Authorization").Type(String).Required(true),
    Returns(401),
    Returns(403)
  );
}
  1. UseAuth(Guard, options) adds the guard as @UseBefore once and merges options into the endpoint store. Read them with $ctx.endpoint.get(AuthMiddleware).
  2. Works on a method or on a class (applies to every endpoint; class-level and method-level options are merged in the endpoint store).
  3. Throw Unauthorized for missing or invalid credentials and Forbidden for insufficient rights.
  4. The Security name must match a security scheme declared in the OpenAPI configuration (tsed-openapi). Passport and OIDC: https://tsed.dev/docs/authentication.md.
Show full SKILL.md (272 more words)Show less

5. Write an interceptor

typescript
import {Interceptor, type InterceptorContext, type InterceptorMethods, type InterceptorNext} from "@tsed/di";

@Interceptor()
export class TimingInterceptor implements InterceptorMethods {
  async intercept(context: InterceptorContext, next: InterceptorNext) {
    const start = Date.now();
    const result = await next();
    console.log(String(context.propertyKey), Date.now() - start, context.options);
    return result;
  }
}
  1. Apply with @Intercept(TimingInterceptor, options) from @tsed/di on a method, or on a class to wrap all its methods. Works on services and controllers.
  2. context exposes target, propertyKey, args, options. Always return the result of next(), or a fallback value.
  3. There is no @UseInterceptor decorator (a doc snippet mentions it by mistake).
  4. Response caching: @UseCache() from @tsed/platform-cache is a ready-made interceptor (GET endpoints and service methods). Setup: https://tsed.dev/docs/cache.md.

6. Write a pipe

typescript
import {Injectable} from "@tsed/di";
import {NotFound} from "@tsed/exceptions";
import type {JsonParameterStore, PipeMethods} from "@tsed/schema";

@Injectable()
export class UserPipe implements PipeMethods<string, Promise<User>> {
  async transform(id: string, metadata: JsonParameterStore) {
    const user = await findUser(id);
    if (!user) throw new NotFound("User not found");
    return user;
  }
}
  1. Use it on a parameter: @RawPathParams("id") @UsePipe(UserPipe) user: User (both from @tsed/platform-params). Use the Raw* decorator when the pipe returns an object, otherwise the built-in deserializer and validator also run on the raw value.
  2. Package it as useDecorators(RawPathParams(expression), UsePipe(UserPipe, options)); read options with metadata.store.get(UserPipe). When a pipe throws, the handler is not called and the error goes to the exception filters.

Pitfalls

  • Class middleware registered with hook: "$afterInit": startup error. Remove the hook or use $beforeRoutesInit.
  • $ctx.endpoint is undefined in a global middleware: the route is not resolved yet. Move the logic to @UseBefore.
  • Calling next() and also returning or throwing: double response. Do not inject @Next() in Ts.ED middlewares.
  • Body is empty: no body parser registered (json-parser / urlencoded-parser).
  • Pipe receives an already mapped value, or validation fails before the pipe: use the Raw* parameter decorator.

Checklist

  • Narrowest mechanism chosen; middleware decorated with @Middleware(), implements use, throws typed exceptions.
  • Global entries use a valid hook; class middlewares are on $beforeRoutesInit or later.
  • Auth decorator documents Security, 401 and 403.
  • No @tsed/common import; relative imports end with .js.
  • Behavior covered by an integration test (see tsed-testing).

Depth: https://tsed.dev/docs/middlewares.md, https://tsed.dev/docs/interceptors.md, https://tsed.dev/docs/pipes.md, https://tsed.dev/docs/authentication.md, https://tsed.dev/docs/request-context.md.

© tsedio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/tsed/skills/tsed-middlewares of tsedio/tsed.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit cc5a0da

Compare with similar skills

Tsed Middlewares next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tsed Middlewares compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tsed Middlewares this skilltsedio/tsed3.1k—~2.4kAutomated safety check: PassMIT
Nodejs Backend Patternsever-works/ever-works16218 repos~4kAutomated safety check: PassAGPL-3.0
Stripe Projectsfossasia/eventyay1.7k5 repos~2kAutomated safety check: NotesApache-2.0
FoundatioFoundatioFx/Foundatio2.1k—~3.9kAutomated safety check: PassApache-2.0
Wp Block Themesgambitph/Stackable3513 repos~985Automated safety check: PassGPL-3.0
Wp Performancegambitph/Stackable3513 repos~1.5kAutomated safety check: PassGPL-3.0

Similar skills

  • Nodejs Backend Patterns

    ever-works/ever-works

    Build production-ready Node.js backend services with Express/Fastify, implementing middleware patterns, error handling, authentication, database integration, and API design best practices.

    162 GitHub starsUsed in 18 repos~4k tokens
    Backend & APIsAuto-check passed
  • Stripe Projects

    fossasia/eventyay

    A skill your agent uses when the user wants to provision infrastructure or third-party services using Stripe Projects.

    1.7k GitHub starsUsed in 5 repos~2k tokens
    Backend & APIsAuto-check: notes
  • Foundatio

    FoundatioFx/Foundatio

    A skill your agent uses when working with Foundatio infrastructure abstractions for .NET -- caching, queuing, messaging, file storage, distributed locking, or background jobs.

    2.1k GitHub stars~3.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Wp Block Themes

    gambitph/Stackable

    A skill your agent uses when developing WordPress block themes: theme.json (global settings/styles), templates and template parts, patterns, style variations, and Site Editor troubleshooting (style…

    351 GitHub starsUsed in 3 repos~985 tokens
    Backend & APIsAuto-check passed
  • Wp Performance

    gambitph/Stackable

    A skill your agent uses when investigating or improving WordPress performance (backend-only agent): profiling and measurement (WP-CLI profile/doctor, Server-Timing, Query Monitor via REST headers)…

    351 GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Effect Portable Patterns

    millionco/expect

    Portable Effect patterns for robust promise execution. An agent skill from millionco/expect.

    3.6k GitHub stars~3.7k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed

More from tsedio/tsed

All 16 skills in this repo
  • Create a production-ready Ts.ED platform adapter for a new HTTP framework or runtime, such as Hono, Elysia, Bun.serve, or a Node framework.

    3.1k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Tsed CLI

    tsedio/tsed

    Scaffolds Ts.ED v8 projects and generates files with the Ts.ED CLI v7, through its MCP server (tools set-workspace, init-project, list-templates, get-template, generate-file) or the tsed binary…

    3.1k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Configure and bootstrap a Ts.ED v8 server - the @Configuration decorator or configuration() on the Server class, PlatformExpress/PlatformKoa/PlatformFastify.bootstrap, server options (mount…

    3.1k GitHub stars~2.1k tokensUpdated today
    Auto-check: notes
  • Tsed Di

    tsedio/tsed

    Declare, inject and scope Ts.ED v8 providers and wire lifecycle hooks - @Injectable, @Module, @Controller, @Inject, the functional API (inject, injectMany, lazyInject, constant, refValue…

    3.1k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Tsed Docs

    tsedio/tsed

    Locates authoritative Ts.ED v8 documentation and API reference instead of guessing framework APIs.

    3.1k GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Tsed Logger

    tsedio/tsed

    Configure and use logging in a Ts.ED v8 application with @tsed/logger v8.

    3.1k GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Tsed Middlewares

What does Tsed Middlewares do?

Add cross-cutting request logic to a Ts.ED v8 application with middlewares, auth guards, interceptors and pipes. Tsed Middlewares is an agent skill from tsedio/tsed.ED v8 application with middlewares, auth guards, interceptors and pipes.

When should I use Tsed Middlewares?

Tsed Middlewares fits situations like: writing a @Middleware class; registering global Express/Koa/Fastify middlewares through the middlewares configuration; $beforeRoutesInit; applying @UseBefore/@Use/@UseAfter/@UseBeforeEach.

How do I install Tsed Middlewares in Claude Code?

Run `npx skills add tsedio/tsed --skill tsed-middlewares -a claude-code`. Or copy the skill folder (plugins/tsed/skills/tsed-middlewares in tsedio/tsed) into .claude/skills/tsed-middlewares in your project. Claude Code loads it when a task matches its description.

How do I install Tsed Middlewares in Codex?

Run `npx skills add tsedio/tsed --skill tsed-middlewares -a codex`. Or copy the skill folder (plugins/tsed/skills/tsed-middlewares in tsedio/tsed) into .agents/skills/tsed-middlewares in your project. Codex loads it when a task matches its description.

Can I use Tsed Middlewares in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add tsedio/tsed --skill tsed-middlewares -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tsed-middlewares, .gemini/skills/tsed-middlewares, .github/skills/tsed-middlewares and .opencode/skills/tsed-middlewares in your project.

What does Tsed Middlewares need to run?

SKILL.md names no scripts, command-line tools or credentials: Tsed Middlewares is instructions for the agent only.

Does Tsed Middlewares access the network?

SKILL.md names 1 domain. As links in the text: tsed.dev. This is read from the text; nothing was executed.

Is Tsed Middlewares safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Tsed Middlewares use?

Tsed Middlewares is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tsed Middlewares use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tsed Middlewares?

Skills that share tags, products or a category with Tsed Middlewares: Nodejs Backend Patterns (ever-works/ever-works, 162 stars), Stripe Projects (fossasia/eventyay, 1.7k stars), Foundatio (FoundatioFx/Foundatio, 2.1k stars) and Wp Block Themes (gambitph/Stackable, 351 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tsed Middlewares?

tsedio (a GitHub organization) maintains it in tsedio/tsed, which has 3,088 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 9, 2026.

Source: tsedio/tsed on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.