AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Nean Code Review

skill-edfenton-claude-skills-nean-code-review · by edfenton

Review NEAN code for compliance with standards, NFRs, and security policy.

No reviews yet
0 installs
33 views
0.0% view→install

Install

$ agentstack add skill-edfenton-claude-skills-nean-code-review

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-edfenton-claude-skills-nean-code-review)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
6mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Nean Code Review? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Purpose

Review code against nean-std, nean-nfr, and nean-sec policies. Report issues, then (with approval) fix and run tests to confirm.

Arguments

  • --paths — Limit review scope (default: whole repo)
  • --no-fix — Report only, don't offer to fix

Workflow

1. Automated gates

npm run lint
npm run format -- --check
npx nx affected --target=typecheck

2. Policy review

Review against:

  • nean-std — coding standards, project structure, conventions
  • nean-nfr — performance, reliability, observability, accessibility
  • nean-sec — input validation, SQL injection prevention, auth, error handling

For each issue, note:

  • Category: std | nfr | sec
  • Severity: must-fix | should-fix | nice-to-have
  • File and location
  • What's wrong and how to fix it

3. Report results

Summary of automated gate results + policy findings grouped by severity.

4–5. Approval gate, fix and confirm

See /shared-review-workflow for severity definitions, approval gate protocol, and fix constraints. Run /nean-unit-test to confirm no regressions after fixes.

Common issues to check

Security (nean-sec)

  • [ ] Raw SQL queries instead of TypeORM query builder
  • [ ] Missing ValidationPipe on controller methods
  • [ ] DTOs without class-validator decorators
  • [ ] Missing guards on protected endpoints
  • [ ] Sensitive data in error responses
  • [ ] Missing rate limiting on auth endpoints

Standards (nean-std)

  • [ ] Business logic in controllers (should be in services)
  • [ ] Missing OpenAPI decorators
  • [ ] Incorrect file/folder naming
  • [ ] Missing barrel exports
  • [ ] Entities exposed directly (should use DTOs)

NFRs (nean-nfr)

  • [ ] Missing pagination on list endpoints
  • [ ] N+1 query patterns
  • [ ] Missing indexes on frequently queried columns
  • [ ] OnPush not used in Angular components
  • [ ] Missing error handling in effects

Reference

For review checklists and common issues, see reference/nean-code-review-reference.md

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.