Skip to content
Back to skills

Api Nestjs Reviewer

ASecurity

Reviews NestJS code for architectural patterns, security issues, multi-tenancy compliance, CQRS enforcement, and best practices

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 27, 2026
securitytypescriptsqlapisecuritydocumentation

Works with

  • api

Security analysis

A100/100

Scanned September 27, 2026

npx -y skills add David-Li0406/meta-skill-evloving --skill api-nestjs-reviewer --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Api Nestjs Reviewer?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Api Nestjs Reviewer
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/david-li0406-api-nestjs-reviewer/badge)](https://www.skillsdirectory.com/skills/david-li0406-api-nestjs-reviewer)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: api-nestjs-reviewer
description: Reviews NestJS code for architectural patterns, security issues, multi-tenancy compliance, CQRS enforcement, and best practices
allowed-tools:
  - Read
  - Grep
  - Glob
  - Edit
---

## Purpose

Reviews NestJS code for architectural patterns, security issues, multi-tenancy compliance, and best practices. Enforces CQRS pattern, proper guards/decorators, event publishing, and tracing.

## Responsibilities

1. **Pattern Validation**
   - Verify CQRS pattern usage (commands, queries, events, handlers)
   - Check multi-tenancy implementation (organization_id everywhere)
   - Validate transaction usage for multi-step writes
   - Ensure proper error handling

2. **Security Review**
   - Check for PII encryption
   - Verify audit logging on state changes
   - Validate authentication/authorization guards
   - Check for SQL injection risks
   - Verify tenant scoping

3. **Code Quality**
   - Verify TypeScript strict mode compliance
   - Check for code duplication
   - Validate naming conventions
   - Ensure proper dependency injection
   - Check for proper event publishing
   - Verify OpenTelemetry tracing

4. **Documentation**
   - Verify OpenAPI documentation completeness
   - Check for meaningful comments
   - Validate DTO descriptions

## Checks Performed

### CQRS Pattern

- [ ] Commands in `commands/` directory
- [ ] Queries in `queries/` directory
- [ ] Events in `events/` directory
- [ ] Handlers properly decorated
- [ ] Commands/queries include `tenantId`
- [ ] Events published after state changes

### Multi-Tenancy

- [ ] Tables have `organization_id` column
- [ ] Queries filter by tenant
- [ ] Controllers extract tenant context
- [ ] Cache keys tenant-prefixed
- [ ] Queue jobs include tenantId

### Security

- [ ] Guards on protected endpoints
- [ ] PII fields encrypted
- [ ] Audit logging on state changes
- [ ] No sensitive data in logs
- [ ] Input validation on all endpoints

### Best Practices

- [ ] Transactions for multi-step writes
- [ ] Proper error handling
- [ ] OpenAPI documentation complete
- [ ] OpenTelemetry tracing
- [ ] Cache invalidation on updates

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…