Nodejs Api
Skill Profile
(Select at least one profile to enable specific modules)
Overview
Node.js REST API is a RESTful API built with Node.js and Express.js framework, using middleware patterns for cross-cutting concerns like authentication, logging, error handling, and validation.
Node.js REST API consists of:
- Express.js: Web framework for building REST APIs
- Middleware Pattern: Chainable middleware for request/response processing
- TypeScript: Type-safe development with TypeScript
- RESTful Design: REST API design principles and best practices
- Layered Architecture: Controller-Service-Repository pattern for separation of concerns
Why This Matters
- Increase Development Speed: Node.js can increase development speed by 2-3x
- Reduce Time-to-Market: Fast development reduces time-to-market
- Improve Maintainability: Layered architecture improves maintainability
- Enhance Developer Experience: TypeScript improves DX with type safety
- Reduce Learning Curve: JavaScript ecosystem has community support and resources
Core Concepts & Rules
1. Core Principles
- Follow established patterns and conventions
- Maintain consistency across codebase
- Document decisions and trade-offs
2. Implementation Guidelines
- Start with the simplest viable solution
- Iterate based on feedback and requirements
- Test thoroughly before deployment
Inputs / Outputs / Contracts
- Inputs:
- API requirements
- Architecture requirements
- Middleware requirements
- Security requirements
- Entry Conditions:
- Node.js 16+ is available
- Express.js is installed
- TypeScript is configured
- API design is defined
- Outputs:
- Express application
- Controllers
- Services
- Repositories
- Artifacts Required (Deliverables):
- Application setup
- Controllers
- Services
- Repositories
- Middleware
- Acceptance Evidence:
- API endpoints work correctly
- Layered architecture is implemented
- Middleware processes requests
- Error handling is consistent
- Success Criteria:
- API is functional
- Architecture is layered
- Middleware is modular
- Error handling is robust
Skill Composition
Quick Start / Implementation Example
- Review requirements and constraints
- Set up development environment
- Implement core functionality following patterns
- Write tests for critical paths
- Run tests and fix issues
- Document any deviations or decisions
# Example implementation following best practices
def example_function():
# Your implementation here
pass
Assumptions / Constraints / Non-goals
- Assumptions:
- Development environment is properly configured
- Required dependencies are available
- Team has basic understanding of domain
- Constraints:
- Must follow existing codebase conventions
- Time and resource limitations
- Compatibility requirements
- Non-goals:
- This skill does not cover edge cases outside scope
- Not a replacement for formal training
Compatibility & Prerequisites
- Supported Versions:
- Python 3.8+
- Node.js 16+
- Modern browsers (Chrome, Firefox, Safari, Edge)
- Required AI Tools:
- Code editor (VS Code recommended)
- Testing framework appropriate for language
- Version control (Git)
- Dependencies:
- Language-specific package manager
- Build tools
- Testing libraries
- Environment Setup:
.env.example keys: API_KEY, DATABASE_URL (no values)
Test Scenario Matrix (QA Strategy)
| Type |
Focus Area |
Required Scenarios / Mocks |
| Unit |
Core Logic |
Must cover primary logic and at least 3 edge/error cases. Target minimum 80% coverage |
| Integration |
DB / API |
All external API calls or database connections must be mocked during unit tests |
| E2E |
User Journey |
Critical user flows to test |
| Performance |
Latency / Load |
Benchmark requirements |
| Security |
Vuln / Auth |
SAST/DAST or dependency audit |
| Frontend |
UX / A11y |
Accessibility checklist (WCAG), Performance Budget (Lighthouse score) |
Technical Guardrails & Security Threat Model
1. Security & Privacy (Threat Model)
- Top Threats: Injection attacks, authentication bypass, data exposure
2. Performance & Resources
3. Architecture & Scalability
4. Observability & Reliability
Agent Directives & Error Recovery
(ข้อกำหนดสำหรับ AI Agent ในการคิดและแก้ปัญหาเมื่อเกิดข้อผิดพลาด)
- Thinking Process: Analyze root cause before fixing. Do not brute-force.
- Fallback Strategy: Stop after 3 failed test attempts. Output root cause and ask for human intervention/clarification.
- Self-Review: Check against Guardrails & Anti-patterns before finalizing.
- Output Constraints: Output ONLY the modified code block. Do not explain unless asked.
Definition of Done (DoD) Checklist
Anti-patterns / Pitfalls
- ⛔ Don't: Log PII, catch-all exception, N+1 queries
- ⚠️ Watch out for: Common symptoms and quick fixes
- 💡 Instead: Use proper error handling, pagination, and logging
Reference Links & Examples
- Internal documentation and examples
- Official documentation and best practices
- Community resources and discussions
Versioning & Changelog
- Version: 1.0.0
- Changelog:
- 2026-02-22: Initial version with complete template structure
Source: AmnadTaowsoam/CerebraSkills — distributed by TomeVault.
1---2name: nodejs-api3description: Node.js REST API is a RESTful API built with Node.js and Express.js framework, Use when this capability is needed.4---56# Nodejs Api78## Skill Profile9*(Select at least one profile to enable specific modules)*10- [ ] **DevOps**11- [x] **Backend**12- [ ] **Frontend**13- [ ] **AI-RAG**14- [ ] **Security Critical**1516## Overview17Node.js REST API is a RESTful API built with Node.js and Express.js framework, using middleware patterns for cross-cutting concerns like authentication, logging, error handling, and validation.1819Node.js REST API consists of:20- **Express.js**: Web framework for building REST APIs21- **Middleware Pattern**: Chainable middleware for request/response processing22- **TypeScript**: Type-safe development with TypeScript23- **RESTful Design**: REST API design principles and best practices24- **Layered Architecture**: Controller-Service-Repository pattern for separation of concerns2526## Why This Matters27- **Increase Development Speed**: Node.js can increase development speed by 2-3x28- **Reduce Time-to-Market**: Fast development reduces time-to-market29- **Improve Maintainability**: Layered architecture improves maintainability30- **Enhance Developer Experience**: TypeScript improves DX with type safety31- **Reduce Learning Curve**: JavaScript ecosystem has community support and resources3233---3435## Core Concepts & Rules3637### 1. Core Principles38- Follow established patterns and conventions39- Maintain consistency across codebase40- Document decisions and trade-offs4142### 2. Implementation Guidelines43- Start with the simplest viable solution44- Iterate based on feedback and requirements45- Test thoroughly before deployment464748## Inputs / Outputs / Contracts49* **Inputs**:50 - API requirements51 - Architecture requirements52 - Middleware requirements53 - Security requirements54* **Entry Conditions**:55 - Node.js 16+ is available56 - Express.js is installed57 - TypeScript is configured58 - API design is defined59* **Outputs**:60 - Express application61 - Controllers62 - Services63 - Repositories64* **Artifacts Required (Deliverables)**:65 - Application setup66 - Controllers67 - Services68 - Repositories69 - Middleware70* **Acceptance Evidence**:71 - API endpoints work correctly72 - Layered architecture is implemented73 - Middleware processes requests74 - Error handling is consistent75* **Success Criteria**:76 - API is functional77 - Architecture is layered78 - Middleware is modular79 - Error handling is robust8081## Skill Composition82* **Depends on**: [error-handling](../error-handling/SKILL.md), [middleware](../middleware/SKILL.md)83* **Compatible with**: [express-rest](../express-rest/SKILL.md), [validation](../validation/SKILL.md)84* **Conflicts with**: None85* **Related Skills**: [api-design](../../01-foundations/api-design/SKILL.md), [monitoring-observability](../../14-monitoring-observability/SKILL.md)8687---8889## Quick Start / Implementation Example90911. Review requirements and constraints922. Set up development environment933. Implement core functionality following patterns944. Write tests for critical paths955. Run tests and fix issues966. Document any deviations or decisions9798```python99# Example implementation following best practices100def example_function():101 # Your implementation here102 pass103```104105106## Assumptions / Constraints / Non-goals107108* **Assumptions**:109 - Development environment is properly configured110 - Required dependencies are available111 - Team has basic understanding of domain112* **Constraints**:113 - Must follow existing codebase conventions114 - Time and resource limitations115 - Compatibility requirements116* **Non-goals**:117 - This skill does not cover edge cases outside scope118 - Not a replacement for formal training119120121## Compatibility & Prerequisites122123* **Supported Versions**:124 - Python 3.8+125 - Node.js 16+126 - Modern browsers (Chrome, Firefox, Safari, Edge)127* **Required AI Tools**:128 - Code editor (VS Code recommended)129 - Testing framework appropriate for language130 - Version control (Git)131* **Dependencies**:132 - Language-specific package manager133 - Build tools134 - Testing libraries135* **Environment Setup**:136 - `.env.example` keys: `API_KEY`, `DATABASE_URL` (no values)137138139## Test Scenario Matrix (QA Strategy)140141| Type | Focus Area | Required Scenarios / Mocks |142| :--- | :--- | :--- |143| **Unit** | Core Logic | Must cover primary logic and at least 3 edge/error cases. Target minimum 80% coverage |144| **Integration** | DB / API | All external API calls or database connections must be mocked during unit tests |145| **E2E** | User Journey | Critical user flows to test |146| **Performance** | Latency / Load | Benchmark requirements |147| **Security** | Vuln / Auth | SAST/DAST or dependency audit |148| **Frontend** | UX / A11y | Accessibility checklist (WCAG), Performance Budget (Lighthouse score) |149150151## Technical Guardrails & Security Threat Model152153### 1. Security & Privacy (Threat Model)154* **Top Threats**: Injection attacks, authentication bypass, data exposure155- [ ] **Data Handling**: Sanitize all user inputs to prevent Injection attacks. Never log raw PII156- [ ] **Secrets Management**: No hardcoded API keys. Use Env Vars/Secrets Manager157- [ ] **Authorization**: Validate user permissions before state changes158159### 2. Performance & Resources160- [ ] **Execution Efficiency**: Consider time complexity for algorithms161- [ ] **Memory Management**: Use streams/pagination for large data162- [ ] **Resource Cleanup**: Close DB connections/file handlers in finally blocks163164### 3. Architecture & Scalability165- [ ] **Design Pattern**: Follow SOLID principles, use Dependency Injection166- [ ] **Modularity**: Decouple logic from UI/Frameworks167168### 4. Observability & Reliability169- [ ] **Logging Standards**: Structured JSON, include trace IDs `request_id`170- [ ] **Metrics**: Track `error_rate`, `latency`, `queue_depth`171- [ ] **Error Handling**: Standardized error codes, no bare except172- [ ] **Observability Artifacts**:173 - **Log Fields**: timestamp, level, message, request_id174 - **Metrics**: request_count, error_count, response_time175 - **Dashboards/Alerts**: High Error Rate > 5%176177178## Agent Directives & Error Recovery179*(ข้อกำหนดสำหรับ AI Agent ในการคิดและแก้ปัญหาเมื่อเกิดข้อผิดพลาด)*180181- **Thinking Process**: Analyze root cause before fixing. Do not brute-force.182- **Fallback Strategy**: Stop after 3 failed test attempts. Output root cause and ask for human intervention/clarification.183- **Self-Review**: Check against Guardrails & Anti-patterns before finalizing.184- **Output Constraints**: Output ONLY the modified code block. Do not explain unless asked.185186187## Definition of Done (DoD) Checklist188189- [ ] Tests passed + coverage met190- [ ] Lint/Typecheck passed191- [ ] Logging/Metrics/Trace implemented192- [ ] Security checks passed193- [ ] Documentation/Changelog updated194- [ ] Accessibility/Performance requirements met (if frontend)195196197## Anti-patterns / Pitfalls198199* ⛔ **Don't**: Log PII, catch-all exception, N+1 queries200* ⚠️ **Watch out for**: Common symptoms and quick fixes201* 💡 **Instead**: Use proper error handling, pagination, and logging202203204## Reference Links & Examples205206* Internal documentation and examples207* Official documentation and best practices208* Community resources and discussions209210211## Versioning & Changelog212213* **Version**: 1.0.0214* **Changelog**:215 - 2026-02-22: Initial version with complete template structure216217---218> Source: [AmnadTaowsoam/CerebraSkills](https://github.com/AmnadTaowsoam/CerebraSkills) — distributed by [TomeVault](https://tomevault.io).219<!-- tomevault:4.0:skill_md:2026-06-15 -->