Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/hmake98/nestjs-starter/gen-endpointgit clone --depth 1 https://github.com/hmake98/nestjs-starterWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/hmake98/nestjs-starter/gen-endpoint)<a href="https://agentmods.dev/commands/hmake98/nestjs-starter/gen-endpoint"><img src="https://agentmods.dev/badge/commands/hmake98/nestjs-starter/gen-endpoint.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00501 |
| Opus 5 | $0.00000 | $0.00251 |
| Sonnet 5 | $0.00000 | $0.00100 |
| Haiku 4.5 | $0.00000 | $0.00050 |
Grade A, and why
gen-endpoint scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Add a new API endpoint to an existing controller: $ARGUMENTS
Read these files first:
src/modules/user/controllers/user.public.controller.ts— public endpoint patternsrc/modules/user/controllers/user.admin.controller.ts— admin endpoint patternsrc/common/doc/decorators/doc.api-endpoint.decorator.ts— @ApiEndpoint optionssrc/common/request/decorators/auth-user.decorator.ts— @AuthUser usagesrc/common/request/decorators/roles.decorator.ts— @AllowedRoles usagesrc/common/response/dtos/response.generic.dto.ts— generic response shape
Determine from the arguments:
- Which controller file to modify
- HTTP method (GET / POST / PUT / PATCH / DELETE)
- Route path and params
- Whether it needs auth (
@ApiBearerAuth), role restriction (@AllowedRoles), or is public (@PublicRoute) - Request body DTO (create if it doesn't exist)
- Response DTO (create if it doesn't exist, extend the base response DTO)
For every new endpoint:
-
Controller method — add to the correct controller with:
@ApiEndpoint({ summary: '...', serialization: ResponseDto, messageKey: '<domain>.success.<action>' })- Correct HTTP decorator (
@Get,@Post,@Put,@Patch,@Delete) @Param,@Body,@Querydecorators as needed@AuthUser() user: IAuthUserif it needs the authenticated user
-
Service method — add to the corresponding service:
- Throws
HttpExceptionwith i18n key andHttpStatusfor all error cases - Returns the response DTO type
- Uses
assertExistsprivate helper for existence pre-checks
- Throws
-
DTOs — if new ones are needed:
- Input DTOs:
class-validatordecorators +@ApiProperty - Response DTOs: extend base response DTO,
@Expose()on each field
- Input DTOs:
-
i18n message key — remind me to add the
messageKeyvalue to the translations file
After adding the endpoint also tell me: does the corresponding service method need a new repository method? If so, describe what it should look like following src/common/database/repositories/user.repository.ts.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 39 lines · 0 tokens per session scan A bd588f3730f2
gen-endpoint is a command published in the GitHub repository hmake98/nestjs-starter (61 stars, last pushed 3mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 501 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
build-fix
Incrementally fix TypeScript and build errors with minimal diffs. Fix one error at a time for safety.
types
Debug and fix TypeScript type errors with systematic analysis and expert guidance.
setup-code-intelligence
Check code-intelligence prerequisites (ripgrep + a language server) and print install hints.
type-crusade
Unleash parallel TypeScript Purist agents to purge every any, as cast, and type sin across the codebase. No type sin survives.
vite-react-setup
Setup project React SPA mới với Vite + TypeScript + Tailwind CSS v3 + Vitest. Dùng khi bắt đầu dự án frontend mới, cần scaffold đầy đủ config, brand KZTEK colors, và test setup sẵn sàng.
typescript
Apply TypeScript best practices and coding standards.