Install
$ agentstack add skill-dkmqflx-nestjs-best-practices-plugin-nestjs-interceptors ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
NestJS Interceptors
Interceptors are @Injectable() classes implementing NestInterceptor. Their intercept(context: ExecutionContext, next: CallHandler) method runs logic before the route handler and transforms the response stream returned by next.handle() using RxJS operators. They are the idiomatic place for cross-cutting concerns — response shaping, logging, timeouts, caching — that should stay out of controllers and services.
When to Apply
Apply these rules when you are:
- Writing or reviewing a class that implements
NestInterceptor. - Wrapping handler responses in a consistent envelope.
- Adding request/response logging or latency measurement.
- Enforcing per-request timeouts.
- Caching GET responses with
CacheInterceptor. - Deciding whether to bind an interceptor globally, per-controller, or per-route.
Do not reach for an interceptor when the work is core business logic — that belongs in a service (see interceptors-not-for-mutation-logic).
Rules
| Rule | Impact | Summary | | --- | --- | --- | | [response-transform-interceptor](rules/response-transform-interceptor.md) | HIGH | Wrap responses in a consistent envelope via map(). | | [logging-interceptor](rules/logging-interceptor.md) | MEDIUM | Measure handler duration with tap(); log method/url/time. | | [timeout-interceptor](rules/timeout-interceptor.md) | HIGH | Fail slow requests with timeout() + RequestTimeoutException. | | [cache-interceptor](rules/cache-interceptor.md) | MEDIUM | Cache GET responses with CacheInterceptor + CacheModule. | | [interceptors-not-for-mutation-logic](rules/interceptors-not-for-mutation-logic.md) | HIGH | Keep business logic in services; interceptors are cross-cutting only. | | [bind-globally-vs-scoped](rules/bind-globally-vs-scoped.md) | MEDIUM | Prefer APP_INTERCEPTOR for DI-friendly global binding. |
How to Use
- Identify the cross-cutting concern (transform, log, timeout, cache).
- Open the matching rule file and follow the Correct pattern.
- Keep
intercept()thin — pipe RxJS operators ontonext.handle(), never
put domain logic inside.
- Choose a binding scope with
bind-globally-vs-scoped: route, controller, or
global via APP_INTERCEPTOR.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: dkmqflx
- Source: dkmqflx/nestjs-best-practices-plugin
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.