Skip to content
Back to skills

Api Dto

ASecurity

Generate DTOs with class-validator decorators, transformation logic, partial update DTOs, and response DTOs that exclude sensitive fields. Use when creating request/response DTOs or adding validation.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
toolsbashapi

Works with

  • api

Security analysis

A100/100

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill api-dto --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Api Dto?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Api Dto
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-api-dto/badge)](https://www.skillsdirectory.com/skills/david-li0406-api-dto)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: api-dto
description: Generate DTOs with class-validator decorators, transformation logic, partial update DTOs, and response DTOs that exclude sensitive fields. Use when creating request/response DTOs or adding validation.
allowed-tools:
  - Read
  - Write
  - Edit
  - Glob
  - Grep
---

# API DTO

## Purpose

Generate Data Transfer Objects (DTOs) with class-validator decorators, transformation logic, partial DTOs for updates, and response DTOs that exclude sensitive fields.

## When to Use

- Creating request/response DTOs
- Adding validation to inputs
- Type-safe API contracts
- Excluding sensitive fields from responses

## What It Generates

### Directory Structure

```
apps/api/src/modules/{feature}/dto/
├── create-{entity}.dto.ts
├── update-{entity}.dto.ts
├── {entity}-response.dto.ts
├── list-{entities}.dto.ts
└── index.ts
```

## Patterns Enforced

### Validation Decorators

Use `class-validator` decorators:

- `@IsString()`, `@IsEmail()`, `@IsUUID()`, etc.
- `@MinLength()`, `@MaxLength()`, etc.
- Custom validation messages
- `@ValidateNested()` for nested objects

### Transformation

Use `class-transformer`:

- `@Transform()` for trimming strings
- `@Type()` for nested type conversion
- Automatic lowercase for emails

### Partial Updates

Update DTOs extend PartialType from `@nestjs/swagger`:

- All fields optional
- Preserves validation on provided fields

### Response DTOs

- Exclude sensitive fields (passwords, tokens)
- Use `@Expose()` for explicit field control
- Transform dates to ISO strings

## Usage Example

```bash
/skill api-dto --name=User --fields='email:email,password:password,name:string,isActive:boolean'
```

## Related Files

- [API Controller](../api-controller/SKILL.md) - Controllers using DTOs
- [Feature CQRS](../feature-cqrs/SKILL.md) - Commands/queries with DTOs

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…