Fullstack code reviewer — Next.js/NestJS review: auth, validation, Prisma, env safety
Review fullstack code against production standards — NestJS auth guards and DTO validation, Prisma safety, Next.js server/client component patterns, shared types, .env hygiene, pre-commit checklist
- What
- Review fullstack code against production standards — NestJS auth guards and DTO validation, Prisma safety, Next.js server/client component patterns, shared types, .env hygiene, pre-commit checklist
- Cost
- Free
- Needs
- a Next.js/NestJS fullstack codebase to review (a diff, a branch, or a pull request)
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — @travisjneuman's generic-fullstack-code-reviewer skill (from the .claude collection): a pre-commit and PR review playbook for Next.js/NestJS full-stack code against production quality standards. The agent validates by reading the diff — never by running a test/lint/build ladder — and checks backend specifics (NestJS auth guards on protected routes, class-validator DTO input validation, Prisma instead of raw SQL with reversible migrations), frontend specifics (Next.js server vs client component patterns, API route validation, shared types keeping request/response contracts consistent), and cross-stack concerns (.env never committed with placeholders in .env.example, Prisma types regenerated, auth and type contracts aligned), with a quick checklist for completing features, before commits, or reviewing pull requests. It extends a base generic code reviewer (P0/P1/P2 priority system) and points to shared standards for code review, design patterns, and UX principles. Honest caveats: opinionated toward one stack — Next.js 16/NestJS/Prisma assumptions don't transfer to other frameworks; review-by-reading catches logic and security issues but won't replace actually running tests. License: the manifest records MIT (the manifest makes faith); the repo frontmatter carries no license field. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: a Next.js/NestJS fullstack codebase to review (a diff, a branch, or a pull request) Install "Fullstack code reviewer — Next.js/NestJS review: auth, validation, Prisma, env safety" for me. It gives my agent @travisjneuman's fullstack review playbook: validate by reading the diff (no test/lint/build ladder), check NestJS auth guards and DTO input validation, Prisma safety (no raw SQL, reversible migrations, regenerated types), Next.js server/client component patterns and API route validation, shared request/response types, and .env hygiene — and run the quick fullstack checklist for completed features, pre-commit, or PR review. MIT licensed (per the discovery manifest; the repo frontmatter carries no license field). Repository: https://github.com/travisjneuman/.claude/blob/main/skills/generic-fullstack-code-reviewer/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "generic-fullstack-code-reviewer". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. point the agent at the diff, branch, or PR to review). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.