nestjs-best-practices
kadajett/agent-nestjs-skills
40 NestJS best practices and architecture patterns for production-ready applications
What is nestjs-best-practices?
Comprehensive guide covering architecture, dependency injection, security, error handling, and performance for NestJS applications. Use when writing, reviewing, or refactoring NestJS code to ensure proper patterns and production readiness.
- Provides 40 prioritized rules across 10 categories (architecture, DI, error handling, security, performance, testing, database, API design, microservices, DevOps)
- Guides module organization, feature-based structure, and circular dependency avoidance
- Enforces dependency injection best practices including constructor injection and scope awareness
- Covers security patterns: JWT authentication, input validation, guards, rate limiting, and output sanitization
- Addresses performance optimization: caching, database query optimization, lazy loading, and async lifecycle hooks
- Includes testing strategies, database transaction management, and microservices patterns
How to install nestjs-best-practices
npx skills add https://github.com/kadajett/agent-nestjs-skills --skill nestjs-best-practicesHow to use nestjs-best-practices
- 1.Install the skill using: npx skills add https://github.com/kadajett/agent-nestjs-skills --skill nestjs-best-practices
- 2.Reference the rule categories by priority (1-10) based on your current focus area
- 3.Read individual rule files (e.g., rules/arch-avoid-circular-deps.md) for detailed explanations and code examples
- 4.Apply the incorrect/correct code examples to your own codebase
- 5.Consult the full compiled AGENTS.md document for complete guidance on all 40 rules
Use cases
- Refactoring an existing NestJS codebase to follow architectural best practices and eliminate anti-patterns
- Building a new production NestJS application with proper module structure, DI, and security from the start
- Implementing authentication and authorization using JWT guards and proper security patterns
- Optimizing database queries and preventing N+1 problems in data-heavy applications
- Setting up microservices architecture with proper health checks, message patterns, and queue handling
- NestJS developers building production applications
- Backend engineers reviewing or refactoring NestJS codebases
- Teams establishing architectural standards for NestJS projects
- Developers implementing security, performance, or testing improvements
nestjs-best-practices FAQ
Start with Architecture (CRITICAL) and Dependency Injection (CRITICAL) categories, as these have the highest impact on code quality and maintainability. Then move to Error Handling and Security (HIGH priority).
Yes, the rules are designed to guide both automated refactoring and manual code review. Each rule includes incorrect and correct code examples for reference.
Yes, there is a dedicated Microservices category (priority 9) covering message patterns, health checks, and background job processing with queues.
Yes, the Testing category (priority 6) covers NestJS testing utilities, E2E testing with Supertest, and mocking external dependencies.
Read individual rule files in the rules/ directory, or view the full compiled document in AGENTS.md in the repository.
Full instructions (SKILL.md)
Source of truth, from kadajett/agent-nestjs-skills.
name: nestjs-best-practices description: NestJS best practices and architecture patterns for building production-ready applications. This skill should be used when writing, reviewing, or refactoring NestJS code to ensure proper patterns for modules, dependency injection, security, and performance. license: MIT metadata: author: Kadajett version: "1.2.0"
NestJS Best Practices
Comprehensive best practices guide for NestJS applications. Contains 40 rules across 10 categories, prioritized by impact to guide automated refactoring and code generation.
When to Apply
Reference these guidelines when:
- Writing new NestJS modules, controllers, or services
- Implementing authentication and authorization
- Reviewing code for architecture and security issues
- Refactoring existing NestJS codebases
- Optimizing performance or database queries
- Building microservices architectures
Rule Categories by Priority
| Priority | Category | Impact | Prefix |
|---|---|---|---|
| 1 | Architecture | CRITICAL | arch- |
| 2 | Dependency Injection | CRITICAL | di- |
| 3 | Error Handling | HIGH | error- |
| 4 | Security | HIGH | security- |
| 5 | Performance | HIGH | perf- |
| 6 | Testing | MEDIUM-HIGH | test- |
| 7 | Database & ORM | MEDIUM-HIGH | db- |
| 8 | API Design | MEDIUM | api- |
| 9 | Microservices | MEDIUM | micro- |
| 10 | DevOps & Deployment | LOW-MEDIUM | devops- |
Quick Reference
1. Architecture (CRITICAL)
arch-avoid-circular-deps- Avoid circular module dependenciesarch-feature-modules- Organize by feature, not technical layerarch-module-sharing- Proper module exports/imports, avoid duplicate providersarch-single-responsibility- Focused services over "god services"arch-use-repository-pattern- Abstract database logic for testabilityarch-use-events- Event-driven architecture for decoupling
2. Dependency Injection (CRITICAL)
di-avoid-service-locator- Avoid service locator anti-patterndi-interface-segregation- Interface Segregation Principle (ISP)di-liskov-substitution- Liskov Substitution Principle (LSP)di-prefer-constructor-injection- Constructor over property injectiondi-scope-awareness- Understand singleton/request/transient scopesdi-use-interfaces-tokens- Use injection tokens for interfaces
3. Error Handling (HIGH)
error-use-exception-filters- Centralized exception handlingerror-throw-http-exceptions- Use NestJS HTTP exceptionserror-handle-async-errors- Handle async errors properly
4. Security (HIGH)
security-auth-jwt- Secure JWT authenticationsecurity-validate-all-input- Validate with class-validatorsecurity-use-guards- Authentication and authorization guardssecurity-sanitize-output- Prevent XSS attackssecurity-rate-limiting- Implement rate limiting
5. Performance (HIGH)
perf-async-hooks- Proper async lifecycle hooksperf-use-caching- Implement caching strategiesperf-optimize-database- Optimize database queriesperf-lazy-loading- Lazy load modules for faster startup
6. Testing (MEDIUM-HIGH)
test-use-testing-module- Use NestJS testing utilitiestest-e2e-supertest- E2E testing with Supertesttest-mock-external-services- Mock external dependencies
7. Database & ORM (MEDIUM-HIGH)
db-use-transactions- Transaction managementdb-avoid-n-plus-one- Avoid N+1 query problemsdb-use-migrations- Use migrations for schema changes
8. API Design (MEDIUM)
api-use-dto-serialization- DTO and response serializationapi-use-interceptors- Cross-cutting concernsapi-versioning- API versioning strategiesapi-use-pipes- Input transformation with pipes
9. Microservices (MEDIUM)
micro-use-patterns- Message and event patternsmicro-use-health-checks- Health checks for orchestrationmicro-use-queues- Background job processing
10. DevOps & Deployment (LOW-MEDIUM)
devops-use-config-module- Environment configurationdevops-use-logging- Structured loggingdevops-graceful-shutdown- Zero-downtime deployments
How to Use
Read individual rule files for detailed explanations and code examples:
rules/arch-avoid-circular-deps.md
rules/security-validate-all-input.md
rules/_sections.md
Each rule file contains:
- Brief explanation of why it matters
- Incorrect code example with explanation
- Correct code example with explanation
- Additional context and references
Full Compiled Document
For the complete guide with all rules expanded in a single document, see AGENTS.md in the repository.
Related skills
More from kadajett/agent-nestjs-skills and the wider catalog.

twitterapi-io
Official skill for twitterapi.io — query Twitter/X data (tweets, profiles, followers, advanced search, trends, spaces, communities, lists) and perform authenticated actions (post, reply, like, retweet, follow, DM) via the twitterapi.io REST API using a single `x-api-key` header — no OAuth. Use when the user needs to scrape, analyze, monitor, or automate X/Twitter without going through the official developer portal.

cangjie-skill
Distill books, videos, podcasts, and courses into executable AI agent skills with frameworks and methodologies.

read-arxiv-paper
Fetch and summarize arXiv papers from their TeX source for local analysis and nanochat integration.

kelos-e2e
Verify Kelos skills.sh installation with a simple marker check.

defuddle
Extract clean Markdown from HTML pages, removing ads and clutter to reduce token usage.

json-canvas
Create and edit JSON Canvas files (.canvas) with nodes, edges, groups, and connections for visual diagrams in Obsidian.