TypeScript Null Safety Guardrails

TypeScript Null Safety Guardrails is a skill for Claude Code from s977043/river-review. It costs 23 tokens per session (958 once invoked), scanned A, original, MIT.

A TypeScript review check for safely handling values that may be missing, such as API responses, query parameters, or optional fields. It also checks that every possible state is handled.

In plain words
What is it for?
It is for reviewing changed TypeScript files and finding unsafe non-null assertions, unchecked external input, and incomplete conditional logic.
Why use it?
It helps reduce runtime errors caused by reading from null or undefined values or overlooking a case.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Part of the river-review plugin — 138 skills, 18 commands, 5 agents, 3 hooks shipped together

Good fit It is for reviewing changed TypeScript files and finding unsafe non-null assertions, unchecked external input, and incomplete conditional logic.

Compare 6 skills from other repositories ↓
Install with agentmods
npx agentmods add skills/s977043/river-review/typescript-nullcheck
Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

Any agent
npx skills add s977043/river-review --skill typescript-nullcheck
Clone the repo
git clone --depth 1 https://github.com/s977043/river-review

Made for: Claude Code.

Or install river-review, the plugin that ships this one along with the rest of its 138 skills, 18 commands, 5 agents, 3 hooks.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for TypeScript Null Safety Guardrails

README.md
[![agentmods](https://agentmods.dev/badge/skills/s977043/river-review/typescript-nullcheck/github.svg)](https://agentmods.dev/skills/s977043/river-review/typescript-nullcheck)
Your own site
<a href="https://agentmods.dev/skills/s977043/river-review/typescript-nullcheck"><img src="https://agentmods.dev/badge/skills/s977043/river-review/typescript-nullcheck/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for TypeScript Null Safety Guardrails

Your own site · 80×15
<a href="https://agentmods.dev/skills/s977043/river-review/typescript-nullcheck"><img src="https://agentmods.dev/badge/skills/s977043/river-review/typescript-nullcheck.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 23 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 958 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00023 $0.00958
Opus 5 $0.00012 $0.00479
Sonnet 5 $0.00005 $0.00192
Haiku 4.5 $0.00002 $0.00096

Measured 5d ago against content hash ccb1a535edbf, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

TypeScript Null Safety Guardrails scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/midstream/typescript-nullcheck/SKILL.md · 81 lines

What it actually says

Pattern declaration

Primary pattern: Reviewer Secondary patterns: Inversion Why: TypeScriptコードの差分からnull/undefinedの安全性をレビューし、実行時エラーシナリオを逆照射する。

Rule / ルール

  • 非同期・外部入力・オプショナル値には null/undefined ガードを設ける。
  • 非 null アサーション(!)や型アサーション(as Foo)に頼らず安全な分岐/early return を使う。
  • ユニオン型は網羅的にハンドリングし、never 到達をチェックする。

Heuristics / 判定の手がかり

  • foo!as Type で未定義かもしれない値を強制している。
  • API レスポンス/環境変数/クエリパラメータをノーチェックで使用。
  • switch/if でユニオン型の全ケースをカバーしていない(defaultで握りつぶし)。
  • Promise 戻りを await せずに使い、undefined アクセスの可能性がある。

Good / Bad Examples

  • Good: if (!value) return err('missing value'); のように early return でガード。
  • Bad: value!.length のような非 null アサーション。
  • Good: switch (state.kind) で各 kind を列挙し、default: assertNever(state) を置く。

Actions / 改善案

  • 外部入力やオプショナル値に対して null/undefined チェックを追加し、早期 return/throw で制御を明確化する。
  • 非 null アサーションを排除し、undefined を許容する型定義やパーサーを導入する。
  • ユニオン型を網羅する switch/if を書き、assertNever などで漏れを検知する。

Non-goals / 扱わないこと

  • 全コードベースの型定義や API 契約の再設計。
  • strict モードの導入可否判断。
  • ライブラリ側の型定義バグの修正。

Pre-execution Gate / 実行前ゲート

このスキルは以下の条件がすべて満たされない限りNO_REVIEWを返す。

  • 差分にTypeScriptファイル(*.ts または *.tsx)が含まれている
  • inputContextにdiffが含まれている

ゲート不成立時の出力: NO_REVIEW: typescript-nullcheck — TypeScriptファイルの差分がない

False-positive guards / 抑制条件

  • null/undefined が型で排除され、追加ガードが不要な箇所。
  • asserts/バリデータで入力が保証されていると明示されている。

評価指標(Evaluation)

  • 合格基準: 指摘が差分に紐づき、根拠と次アクションが説明されている。
  • 不合格基準: 差分と無関係な指摘、根拠のない断定、抑制条件の無視。

人間に返す条件(Human Handoff)

  • 仕様や意図が不明確で解釈が分かれる場合は質問として返す。
  • 影響範囲が広い設計判断やトレードオフは人間レビューへ返す。
Files

What ships with it

6 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 81 lines · 23 tokens per session scan A ccb1a535edbf

Subscribe to this mod's changes

TypeScript Null Safety Guardrails is a skill published in the GitHub repository s977043/river-review (3 stars, last pushed today), licensed MIT. It adds 23 tokens to every session and 958 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

react-frontend

React, TypeScript, and Next.js patterns for frontend development. Use when building React components, managing state, fetching data, optimizing performance, or working with Next.js App Router. Covers React 18-19, hooks, Server Components, and type-safe patterns.

iliaal/whetstone · 57 tokens

review-all

Multi-agent code review for diffs (project-agnostic). Covers standards, bugs, security, DRY, smells, perf, tests, API contracts, a11y/i18n. Verifies each finding to eliminate false positives. Use for /review-all, pre-PR/pre-commit review, or auditing uncommitted/staged changes.

ncoevoet/claude-review-all · 74 tokens

logic-health

Sweep a directory, module, or full codebase for logic correctness and produce a scored health dashboard with systemic patterns. Trigger when the user requests a health view — "audit the whole codebase", "health check", "health overview", "logic health overview", "audit src/", "audit auth and payments modules", "where…

hyhmrright/logic-lens · 180 tokens

ia-c-systems

C patterns for systems code, libraries, and native extensions: module layout, function decomposition, status-enum errors, memory safety, undefined behavior, and performance measurement. Use when writing, reviewing, refactoring, or debugging C, working with malloc lifetimes, buffer overflows, sanitizers, or Valgrind…

iliaal/whetstone · 84 tokens

code-quality-analysis

Analyze Angular / Cumulocity Web SDK code for anti-patterns, bugs, and quality issues. Use when reviewing components, services, or modules for code quality, maintainability, performance, and correctness. Covers TypeScript best practices, Angular idioms, C8Y SDK usage patterns, and project-specific conventions.…

Cumulocity-IoT/cumulocity-skills · 90 tokens

non-null-assertion

Do not use non-null assertion operator (!) in TypeScript. Use optional chaining, type guards, or nullish checks instead. Use when writing or reviewing TypeScript code.

ncaq/konoka · 40 tokens