Nean code review
A collection of Claude Code skills for iOS, MERN, NEAN, and shared development workflows
npx -y skills add edfenton/claude-skills --skill nean-code-reviewAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Review NEAN code for compliance with standards, NFRs, and security policy.
SKILL.md
2.2 KB, as published. Nobody here has run it
Purpose
Review code against nean-std, nean-nfr, and nean-sec policies. Report issues, then (with approval) fix and run tests to confirm.
Arguments
--paths <glob>— Limit review scope (default: whole repo)--no-fix— Report only, don't offer to fix
Workflow
1. Automated gates
npm run lint
npm run format -- --check
npx nx affected --target=typecheck
2. Policy review
Review against:
- nean-std — coding standards, project structure, conventions
- nean-nfr — performance, reliability, observability, accessibility
- nean-sec — input validation, SQL injection prevention, auth, error handling
For each issue, note:
- Category:
std|nfr|sec - Severity:
must-fix|should-fix|nice-to-have - File and location
- What's wrong and how to fix it
3. Report results
Summary of automated gate results + policy findings grouped by severity.
4–5. Approval gate, fix and confirm
See /shared-review-workflow for severity definitions, approval gate protocol, and fix constraints. Run /nean-unit-test to confirm no regressions after fixes.
Common issues to check
Security (nean-sec)
- Raw SQL queries instead of TypeORM query builder
- Missing ValidationPipe on controller methods
- DTOs without class-validator decorators
- Missing guards on protected endpoints
- Sensitive data in error responses
- Missing rate limiting on auth endpoints
Standards (nean-std)
- Business logic in controllers (should be in services)
- Missing OpenAPI decorators
- Incorrect file/folder naming
- Missing barrel exports
- Entities exposed directly (should use DTOs)
NFRs (nean-nfr)
- Missing pagination on list endpoints
- N+1 query patterns
- Missing indexes on frequently queried columns
- OnPush not used in Angular components
- Missing error handling in effects
Reference
For review checklists and common issues, see reference/nean-code-review-reference.md