nestjs-security-isolation
Enforce multi-tenant isolation and PostgreSQL Row Level Security in NestJS. Use when enforcing tenant isolation or PostgreSQL RLS in NestJS multi-tenant apps.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 5
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 638db34c4723b04e… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Priority: P0 (CRITICAL)
Strict multi-tenant isolation. All child-centric data must secured via PostgreSQL RLS and service-level validation.
RLS Enforcement Workflow
- Migration: Create tables with
ENABLE ROW LEVEL SECURITY. Define policies usingcurrent_setting('app.current_user_id'). - Entity Logic: Add
@SecurityJSDoc to entity class. - Security Doc: Update
SECURITY.mdwith new table and its access logic. - Service Validation: Call
childrenService.validateChildAccess(childId, userId)before any persistence operation.
Core Guidelines
- Mandatory RLS: Every new table linking to
childorfamilyMUST RLS enabled in its creation migration. - Centralized Validation: Never reimplement access logic. Use
ChildrenServicefor child/family membership checks. - Traceable Security:
SECURITY.mdsource of truth. Any change to RLS policies must reflected there immediately. - Nested Route Constraint: Data isolation enforced at controller level via nested routes:
/children/:childId/.... - No Direct Entity exposure: Use Response DTOs to prevent leaking internal database IDs or metadata that could circumvent security checks.
Anti-Patterns
- No Public Tables: Don't create child-linked tables without RLS.
- No Manual Policy Checks: Don't write raw SQL access checks in services. Use centralized validator.
- No Stale Docs: Don't merge RLS changes without updating
SECURITY.mdand entity JSDoc. - No Root IDs: Don't use
/domain/:idfor child data. Always scope by:childId.
References
Files
5- SKILL.md
c43c802fa02.1 KB - evals/evals.json
d761fb649d2.3 KB - references/auth-logic.md
aa0f3a7c211.0 KB - references/implementation-patterns.md
459f75d0791.1 KB - references/rls-patterns.md
086636a800923 B
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from HoangNguyen0403/agent-skills-standard8
Upgrade an Android project to Android Gradle Plugin (AGP) 9. Use when migrating to AGP 9, updating Gradle build files, migrating to built-in Kotlin, or adopting the new AGP DSL.
Apply Clean Architecture layering, modularization, and Unidirectional Data Flow in Android projects. Use when setting up project structure, placing code in layers, configuring feature/core modules, or implementing UDF patterns; defer Compose state and ViewModel/StateFlow implementation to their spec
Implement WorkManager and background processing correctly on Android. Use when creating Worker classes, scheduling tasks, choosing between WorkManager and Foreground Services, or setting up Hilt in workers; defer FCM and notification delivery to android-notifications.
Build high-performance declarative UI with Jetpack Compose. Use when writing Composable functions, optimizing recomposition, hoisting state, or working with LazyColumn and side effects; defer deep-link and navigation routing to android-navigation.
Migrate an Android XML View to Jetpack Compose following a structured 10-step workflow. Use when converting XML layouts to Compose, setting up Compose in an existing View-based project, or incrementally adopting Compose.
Write correct coroutine scopes, lifecycle collection, and dispatcher injection in Android production code. Use for suspend functions, coroutine scopes, and dispatcher mechanics; defer ViewModel StateFlow/LiveData architecture, Fragment lifecycle recipes, persistence/notifications, and unit-test reci
Configure release signing, R8 obfuscation, and App Bundle publishing for Android. Use when setting up signing configs, enabling minification, adding ProGuard keep rules, or preparing for Play Store submission.
Enforce Material Design 3 theming and design token usage in Jetpack Compose. Use when implementing M3 components, color schemes, typography, or design tokens.
Related backend skillsscan passed
PostHog integration for FastAPI applications
Java coding standards for Spring Boot and Quarkus services: naming, immutability, Optional usage, streams, exceptions, generics, CDI, reactive patterns, and project layout. Automatically applies framework-specific conventions. Use when writing or reviewing Java in a Spring Boot or Quarkus service.
Report browser/API/CLI/job/worker/webhook bugs. (gstack)
This skill should be used when the user asks to "build an MCP server", "create an MCP", "make an MCP integration", "wrap an API for Claude", "expose tools to Claude", "make an MCP app", or discusses building something with the Model Context Protocol. It is the entry point for MCP server development
Identifies external providers, merchants, nonprofits, platforms, APIs, and software services, and resolves the documented way to engage them — to pay, donate, subscribe, book, provision, or integrate with them. MUST be used BEFORE web search, model memory, or any other directory/vendor-lookup skill
Create and compose tRPC middleware with t.procedure.use(), extend context via opts.next({ ctx }), build reusable middleware with .concat() and .unstable_pipe(), define base procedures like publicProcedure and authedProcedure. Access raw input with getRawInput(). Logging, timing, OTEL tracing pattern