Skip to content
Development
Skill

/nestjs-file-uploads

Validate and stream file uploads securely with Validation and S3 streaming in NestJS. Use when implementing secure file uploads, validation, or S3 streaming in NestJS.

From plugin
agent-skills-standard
538200 skills1 MCP
Install
$ npx -y skills add hoangnguyen0403/agent-skills-standard --skill nestjs-file-uploads --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/nestjs-file-uploads

Context preview

The summary Claude sees to decide when to auto-load this skill.

Validate and stream file uploads securely with Validation and S3 streaming in NestJS. Use when implementing secure file uploads, validation, or S3 streaming in NestJS.

SKILL.md

nestjs-file-uploads.SKILL.md
name: nestjs-file-uploads
description: Validate and stream file uploads securely with Validation and S3 streaming in NestJS. Use when implementing secure file uploads, validation, or S3 streaming in NestJS.
metadata:
  triggers:
    files:
    - '**/*.controller.ts'
    keywords:
    - FileInterceptor
    - Multer
    - S3
    - UploadedFile

File Upload Patterns

**Priority: P0 (CRITICAL)**

  • **Magic Bytes**: NEVER trust `content-type` header or file extension.
  • **Tool**: Use `file-type` or `mmmagic` to verify actual buffer signature.
  • **Limits**: Set strict `limits: { fileSize: 5000000 }` (5MB) in Multer config to prevent DoS.

Streaming (Scalability)

  • **Memory Warning**: Default Multer `MemoryStorage` crashes servers with large files.
  • **Pattern**: Use **Streaming** for any file > 10MB.
  • **Library**: `multer-s3` (direct upload to bucket) or `busboy` (raw stream processing).
  • **Architecture**:

1. Client requests Signed URL from API. 2. Client uploads directly to S3/GCS (Bypassing API server completely). 3. **Pro Tip**: Only approach to scale file uploads infinitely.

Processing

  • **Async**: Don't process images/videos in HTTP Request.
  • **Flow**:

1. Upload file. 2. Push `FileUploadedEvent` to Queue (BullMQ). 3. Worker downloads, resizes/converts, and re-uploads.

Anti-Patterns

  • **No content-type trust**: Always verify file magic bytes; MIME header can spoofed.
  • **No MemoryStorage for large files**: Use streaming or signed URL pattern for files > 10MB.
  • **No synchronous file processing**: Offload image/video work to BullMQ workers via FileUploadedEvent.

References

Read more
Ships withagent-skills-standard

The portable SDLC standards layer for AI coding agents. Sync once, then work in your own runtime.

Get the whole plugin

Other skills on agent-skills-standard.