nestjs-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a collection of educational content and reference documentation for the NestJS framework. It provides patterns for authentication (JWT, Passport, OAuth2), database integration (TypeORM, Prisma, Drizzle), microservices (TCP, Redis, NATS, Kafka), and request lifecycle management (Middleware, Guards, Interceptors, Pipes).
- [SAFE]: Hardcoded credentials are not present; the skill correctly demonstrates the use of placeholders (e.g.,
YOUR_API_KEY_HERE) or environment variable retrieval viaConfigService(e.g.,config.get('JWT_SECRET')). - [SAFE]: External dependencies referenced in the documentation (via
npm install) are standard, well-known libraries within the Node.js and NestJS ecosystem, such as@nestjs/passport,class-validator,typeorm, andprisma. - [SAFE]: The documentation actively promotes security best practices, such as cautioning against using the TypeORM
synchronizeoption in production and recommending the use of thewhitelistproperty inValidationPipeto prevent mass assignment vulnerabilities. - [SAFE]: No obfuscation, prompt injection, or malicious persistence mechanisms were detected in any of the skill files.
Audit Metadata