Compile
apache/skywalking-nodejs
Compile / build / type-check the skywalking-nodejs agent. An agent skill from apache/skywalking-nodejs.
Official agent skill
Security analysis for the Azure Functions Node.js worker. An agent skill from Azure/azure-functions-nodejs-worker.
$ npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Azure/azure-functions-nodejs-worker azure-functions-node-worker-security --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Azure/azure-functions-nodejs-worker.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/azure-functions-node-worker-security .claude/skills/azure-functions-node-worker-security && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azure-functions-node-worker-security" agent skill from https://github.com/Azure/azure-functions-nodejs-worker/tree/v3.x/.github/skills/azure-functions-node-worker-security into .claude/skills/azure-functions-node-worker-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-functions-node-worker-security", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Azure/azure-functions-nodejs-worker/tree/v3.x/.github/skills/azure-functions-node-worker-securityType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Azure/azure-functions-nodejs-worker azure-functions-node-worker-security --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/azure-functions-nodejs-worker.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/azure-functions-node-worker-security .agents/skills/azure-functions-node-worker-security && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azure-functions-node-worker-security" agent skill from https://github.com/Azure/azure-functions-nodejs-worker/tree/v3.x/.github/skills/azure-functions-node-worker-security into .agents/skills/azure-functions-node-worker-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-functions-node-worker-security", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Azure/azure-functions-nodejs-worker azure-functions-node-worker-security --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/azure-functions-nodejs-worker.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/azure-functions-node-worker-security .cursor/skills/azure-functions-node-worker-security && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azure-functions-node-worker-security" agent skill from https://github.com/Azure/azure-functions-nodejs-worker/tree/v3.x/.github/skills/azure-functions-node-worker-security into .cursor/skills/azure-functions-node-worker-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-functions-node-worker-security", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Azure/azure-functions-nodejs-worker.git --path .github/skills/azure-functions-node-worker-security--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Azure/azure-functions-nodejs-worker azure-functions-node-worker-security --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/azure-functions-nodejs-worker.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/azure-functions-node-worker-security .gemini/skills/azure-functions-node-worker-security && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azure-functions-node-worker-security" agent skill from https://github.com/Azure/azure-functions-nodejs-worker/tree/v3.x/.github/skills/azure-functions-node-worker-security into .gemini/skills/azure-functions-node-worker-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-functions-node-worker-security", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Azure/azure-functions-nodejs-worker azure-functions-node-worker-securityInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Azure/azure-functions-nodejs-worker.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/azure-functions-node-worker-security .github/skills/azure-functions-node-worker-security && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azure-functions-node-worker-security" agent skill from https://github.com/Azure/azure-functions-nodejs-worker/tree/v3.x/.github/skills/azure-functions-node-worker-security into .github/skills/azure-functions-node-worker-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-functions-node-worker-security", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Azure/azure-functions-nodejs-worker azure-functions-node-worker-security --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/azure-functions-nodejs-worker.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/azure-functions-node-worker-security .opencode/skills/azure-functions-node-worker-security && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azure-functions-node-worker-security" agent skill from https://github.com/Azure/azure-functions-nodejs-worker/tree/v3.x/.github/skills/azure-functions-node-worker-security into .opencode/skills/azure-functions-node-worker-security/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-functions-node-worker-security", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azure-functions-node-worker-securitySecurity analysis for the Azure Functions Node.js worker. An agent skill from Azure/azure-functions-nodejs-worker.
Azure Functions Node Worker Security is an agent skill from Azure/azure-functions-nodejs-worker, published by the product's own GitHub organization. Security analysis for the Azure Functions Node.js worker. Use automatically or as /azure-functions-node-worker-security when code or a proposed change touches Host RPC input, function metadata, paths, package or module loading, require/import/eval, environment variables, process state, invocation data, protobuf conversion, hooks, logs, errors, credentials, gRPC transport, dependencies, build/release files, denial of service, or cross-invocation isolation. Identify evidence-backed vulnerabilities, rank severity…
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/threat-model.md`).
It sits in Backend & APIs, covering gRPC and Protobuf and Secrets management. It works with Azure Functions, gRPC and Node.js. The repository describes itself as: The Node.js worker for the Azure Functions runtime - https://functions.azure.com. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 8c3b7f3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmnpxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azure Functions Node Worker Security loads about 2.4k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 156 tokens; SKILL.md has 1,107 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Azure/azure-functions-nodejs-worker at commit 8c3b7f3, republished under its MIT licence (© Azure). 1,107 words, ~2,448 tokens.
.claude/skills/azure-functions-node-worker-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Perform a focused security analysis of the requested change or flow. Also apply the azure-functions-node-worker domain skill so findings respect the Host-worker contract and Node.js process model.
Read threat-model.md when analyzing a trust-boundary crossing, dynamic code loading, transport, process-wide state, or dependency change.
A security finding requires all of the following:
Do not report a vulnerability from a sensitive API name alone. Separate confirmed vulnerabilities from defense-in-depth improvements, hardening suggestions, and questions about the Host contract.
Identify the changed behavior, not only changed files. State which properties matter:
For a code-writing task, analyze the proposed data flow before editing and re-check the actual diff afterward. For a review task, inspect changed lines plus the nearest validators, callers, sinks, and tests.
Choose the relevant source explicitly:
The Host is normally a privileged peer, not an anonymous remote client. Findings that require a compromised Host must be labeled defense in depth unless the supported boundary says otherwise.
Trace concrete values through the worker:
source -> parser/decoder -> validation/canonicalization -> state/converter -> sensitive sink -> observable impact
Review the applicable sinks:
require, dynamic import, entry-point lookup, package main, and glob expansionprocess.env, process listeners, termination, module cache, timers, and global app stateTry to disprove each candidate issue before reporting it:
Test boundary values appropriate to the flow, including missing/null values, maximum sizes, duplicate or unexpected map keys, malformed encoded data, mixed path separators, absolute/drive-relative/UNC paths, traversal segments, symlinks, circular error objects, secret-bearing URLs, concurrent invocations, specialization during outstanding work, and hooks that throw or never settle.
Do not create exploit files outside the test workspace, access real credentials, contact production endpoints, or print discovered secret values. Use synthetic values and repository test fixtures.
Run the nearest security regression first, then the domain-required checks. Typical focused commands are:
npx mocha -r ts-node/register "test/errors.test.ts"
npx mocha -r ts-node/register "test/loadScriptFile.test.ts"
npx mocha -r ts-node/register "test/eventHandlers/FunctionEnvironmentReloadHandler.test.ts"
npx mocha -r ts-node/register "test/eventHandlers/InvocationHandler.test.ts"For dependency changes, inspect the manifest and lockfile diff and run npm audit --omit=dev when a lockfile and network access are available. Never run npm audit fix, replace packages, or accept a major update automatically. Verify runtime reachability and review install/build scripts instead of treating an advisory count as proof of exploitability.
Complete applicable repository checks:
npm run lint
npm test
npm run buildUse npm run webpack for bundle or package changes and npm run host-sanity for Host-boundary changes when prerequisites are available.
List findings first, ordered by severity. For each finding include:
Severity and confidenceHuman review required: yes/no with the triggerUse severity based on realistic impact and exploitability:
If there are no evidence-backed findings, say so and list only residual assumptions or untested security boundaries. Do not inflate severity because a file is critical.
grpc.credentials.createInsecure() for a Host-provided trusted localhost endpoint is an explicit compatibility mode, not automatically a vulnerability.eval used only to preserve a dynamic import() through TypeScript compilation is not code injection unless untrusted text becomes executable syntax outside the intended module specifier.rpc.js, rpc_static.js, and rpc.d.ts should be reviewed against .proto source, not treated as independent hand-written flaws.Any change that affects a listed trust boundary, executable-code selection, sanitization, process lifecycle, protocol compatibility, or runtime dependencies must also apply azure-functions-node-worker-critical-path and receive human review.
© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in .github/skills/azure-functions-node-worker-security of Azure/azure-functions-nodejs-worker.
Open the folder on GitHubat commit 8c3b7f3
Azure Functions Node Worker Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azure Functions Node Worker Security this skillAzure/azure-functions-nodejs-worker | 110 | — | ~2.4k | Automated safety check: Pass | MIT | |
| Compileapache/skywalking-nodejs | 180 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Fishjam JS Server SDKsoftware-mansion-labs/skills | 291 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Adding Personhog RpcPostHog/posthog-foss | 721 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Cortexdb Memory Openclawliliang-cn/cortexdb | 273 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Use Yaakmountain-loop/yaak | 19k | — | ~1.9k | Automated safety check: Pass | MIT |
apache/skywalking-nodejs
Compile / build / type-check the skywalking-nodejs agent. An agent skill from apache/skywalking-nodejs.
software-mansion-labs/skills
Node.js / TypeScript server SDK for Fishjam — backends that create rooms, mint peer tokens, listen to server notifications, and run agents.
PostHog/posthog-foss
Guide for adding a new RPC to personhog-replica and personhog-router.
liliang-cn/cortexdb
Give a Node.js agent (such as OpenClaw) durable, local-first memory plus a queryable SPARQL knowledge graph, backed by CortexDB through its gRPC sidecar and the cortexdb-client npm package.
mountain-loop/yaak
A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…
antoniopaya22/go-rest-template
Implements concurrent Go patterns using goroutines and channels, designs and builds microservices with gRPC or REST, optimizes Go application performance with pprof, and enforces idiomatic Go with…
Azure/azure-functions-nodejs-worker
Repository-specific Azure Functions Node.js Host-worker architecture and change-validation workflow.
Azure/azure-functions-nodejs-worker
Mandatory human-intervention gate for critical Azure Functions Node.js worker code.
Works with
Categories
Security analysis for the Azure Functions Node.js worker. An agent skill from Azure/azure-functions-nodejs-worker. Azure Functions Node Worker Security is an agent skill from Azure/azure-functions-nodejs-worker, published by the product's own GitHub organization.js worker.
Azure Functions Node Worker Security fits situations like: tasks that involve gRPC and Protobuf; tasks that involve Secrets management.
Run `npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a claude-code`. Or copy the skill folder (.github/skills/azure-functions-node-worker-security in Azure/azure-functions-nodejs-worker) into .claude/skills/azure-functions-node-worker-security in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a codex`. Or copy the skill folder (.github/skills/azure-functions-node-worker-security in Azure/azure-functions-nodejs-worker) into .agents/skills/azure-functions-node-worker-security in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-functions-node-worker-security, .gemini/skills/azure-functions-node-worker-security, .github/skills/azure-functions-node-worker-security and .opencode/skills/azure-functions-node-worker-security in your project.
Going by SKILL.md and its folder, Azure Functions Node Worker Security needs the command-line tools its instructions call (npm and npx). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azure Functions Node Worker Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Azure Functions Node Worker Security: Compile (apache/skywalking-nodejs, 180 stars), Fishjam JS Server SDK (software-mansion-labs/skills, 291 stars), Adding Personhog Rpc (PostHog/posthog-foss, 721 stars) and Cortexdb Memory Openclaw (liliang-cn/cortexdb, 273 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Azure (a GitHub organization, an official publisher) maintains it in Azure/azure-functions-nodejs-worker, which has 110 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 3, 2026.
Source: Azure/azure-functions-nodejs-worker on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.