Official agent skill

Azure Functions Node Worker Security

by Azure in Azure/azure-functions-nodejs-worker

Security analysis for the Azure Functions Node.js worker. An agent skill from Azure/azure-functions-nodejs-worker.

OfficialMITAuto-check passedBackend & APIs

Install Azure Functions Node Worker Security

skills CLI
$ npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/azure-functions-nodejs-worker azure-functions-node-worker-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/azure-functions-nodejs-worker.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/azure-functions-node-worker-security .claude/skills/azure-functions-node-worker-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-functions-node-worker-security
GitHub stars
110
Token cost
~2.4k tokens
SKILL.md length
1,107 words
Files
2 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

Security analysis for the Azure Functions Node.js worker. An agent skill from Azure/azure-functions-nodejs-worker.

  • Works in 6 steps: Set Scope and Security Properties → Establish the Threat Actor → Trace Source to Sink → …
  • Tasks that involve gRPC and Protobuf
  • SKILL.md covers Security Standard, Required Workflow, Repository-Specific Checks and False-Positive Guardrails
  • Calls npm and npx

What it does

Azure Functions Node Worker Security is an agent skill from Azure/azure-functions-nodejs-worker, published by the product's own GitHub organization. Security analysis for the Azure Functions Node.js worker. Use automatically or as /azure-functions-node-worker-security when code or a proposed change touches Host RPC input, function metadata, paths, package or module loading, require/import/eval, environment variables, process state, invocation data, protobuf conversion, hooks, logs, errors, credentials, gRPC transport, dependencies, build/release files, denial of service, or cross-invocation isolation. Identify evidence-backed vulnerabilities, rank severity…

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/threat-model.md`).

It sits in Backend & APIs, covering gRPC and Protobuf and Secrets management. It works with Azure Functions, gRPC and Node.js. The repository describes itself as: The Node.js worker for the Azure Functions runtime - https://functions.azure.com. The licence is MIT.

When your agent uses it

  • Tasks that involve gRPC and Protobuf
  • Tasks that involve Secrets management

Example prompts

  • “/azure-functions-node-worker-security”

Requirements

  • Node.js

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Set Scope and Security Properties
  2. Establish the Threat Actor
  3. Trace Source to Sink
  4. Test the Hypothesis
  5. Validate the Fix or Finding
  6. Report Findings

What it can do on your machine

Read from SKILL.md and the folder at commit 8c3b7f3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Functions Node Worker Security loads about 2.4k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 156 tokens; SKILL.md has 1,107 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~156
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/azure-functions-nodejs-worker at commit 8c3b7f3, republished under its MIT licence (© Azure). 1,107 words, ~2,448 tokens.

Download SKILL.mdSave it as .claude/skills/azure-functions-node-worker-security/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
azure-functions-node-worker-security
description
Security analysis for the Azure Functions Node.js worker. Use automatically or as /azure-functions-node-worker-security when code or a proposed change touches Host RPC input, function metadata, paths, package or module loading, require/import/eval, environment variables, process state, invocation data, protobuf conversion, hooks, logs, errors, credentials, gRPC transport, dependencies, build/release files, denial of service, or cross-invocation isolation. Identify evidence-backed vulnerabilities, rank severity, avoid expected-behavior false positives, and define regression tests.
argument-hint
[diff, file, flow, or security concern]
user-invocable
true
disable-model-invocation
false

Azure Functions Node.js Worker Security

Perform a focused security analysis of the requested change or flow. Also apply the azure-functions-node-worker domain skill so findings respect the Host-worker contract and Node.js process model.

Read threat-model.md when analyzing a trust-boundary crossing, dynamic code loading, transport, process-wide state, or dependency change.

Security Standard

A security finding requires all of the following:

  1. A security property that should hold.
  2. An attacker or less-trusted source that can influence data or control flow.
  3. A concrete source-to-sink path in this repository.
  4. Preconditions that are possible under the documented deployment model.
  5. A credible confidentiality, integrity, availability, or isolation impact.
  6. Evidence that existing validation or an upstream trust guarantee does not already prevent the path.

Do not report a vulnerability from a sensitive API name alone. Separate confirmed vulnerabilities from defense-in-depth improvements, hardening suggestions, and questions about the Host contract.

Required Workflow

1. Set Scope and Security Properties

Identify the changed behavior, not only changed files. State which properties matter:

  • only the intended Host endpoint can control the worker
  • only intended function-app code and exports are loaded
  • RPC and invocation data retain type, size, and binding boundaries
  • credentials and sensitive data do not cross logs or error responses
  • one app, specialization, or invocation does not inherit unintended state from another
  • malformed or adversarial input cannot crash, hang, or exhaust the worker disproportionately
  • generated artifacts and shipped dependencies correspond to reviewed sources

For a code-writing task, analyze the proposed data flow before editing and re-check the actual diff afterward. For a review task, inspect changed lines plus the nearest validators, callers, sinks, and tests.

2. Establish the Threat Actor

Choose the relevant source explicitly:

  • function-app author controlling package metadata and executable app files
  • external caller controlling trigger or binding data delivered through the Host
  • privileged Azure Functions Host sending lifecycle, metadata, and invocation messages
  • local process or network actor able to reach a configured worker endpoint
  • package publisher or compromised build input

The Host is normally a privileged peer, not an anonymous remote client. Findings that require a compromised Host must be labeled defense in depth unless the supported boundary says otherwise.

3. Trace Source to Sink

Trace concrete values through the worker:

source -> parser/decoder -> validation/canonicalization -> state/converter -> sensitive sink -> observable impact

Review the applicable sinks:

  • require, dynamic import, entry-point lookup, package main, and glob expansion
  • filesystem access, path resolution, drive/UNC handling, symlinks, and working-directory changes
  • process.env, process listeners, termination, module cache, timers, and global app state
  • protobuf decoding/verification, converters, buffers, JSON, binding maps, and response construction
  • gRPC endpoint selection, credentials, message-size limits, and stream error handling
  • logs, exception messages/stacks, hook-transformed logs, and sanitization
  • retries, synchronous work, unbounded collections, recursion, allocation, and user-controlled output
  • package manifests, lockfiles, generation scripts, webpack, NuGet packaging, and pipelines
4. Test the Hypothesis

Try to disprove each candidate issue before reporting it:

  • find upstream validation or a Host guarantee
  • verify whether the source is actually attacker-controlled
  • verify whether the sink is reachable in production
  • distinguish process-wide behavior that is intentional for one function app
  • construct the smallest safe regression test for the claimed boundary

Test boundary values appropriate to the flow, including missing/null values, maximum sizes, duplicate or unexpected map keys, malformed encoded data, mixed path separators, absolute/drive-relative/UNC paths, traversal segments, symlinks, circular error objects, secret-bearing URLs, concurrent invocations, specialization during outstanding work, and hooks that throw or never settle.

Do not create exploit files outside the test workspace, access real credentials, contact production endpoints, or print discovered secret values. Use synthetic values and repository test fixtures.

5. Validate the Fix or Finding

Run the nearest security regression first, then the domain-required checks. Typical focused commands are:

powershell
npx mocha -r ts-node/register "test/errors.test.ts"
npx mocha -r ts-node/register "test/loadScriptFile.test.ts"
npx mocha -r ts-node/register "test/eventHandlers/FunctionEnvironmentReloadHandler.test.ts"
npx mocha -r ts-node/register "test/eventHandlers/InvocationHandler.test.ts"

For dependency changes, inspect the manifest and lockfile diff and run npm audit --omit=dev when a lockfile and network access are available. Never run npm audit fix, replace packages, or accept a major update automatically. Verify runtime reachability and review install/build scripts instead of treating an advisory count as proof of exploitability.

Complete applicable repository checks:

powershell
npm run lint
npm test
npm run build

Use npm run webpack for bundle or package changes and npm run host-sanity for Host-boundary changes when prerequisites are available.

Show full SKILL.md (425 more words)Show less
6. Report Findings

List findings first, ordered by severity. For each finding include:

  • Severity and confidence
  • affected file and symbol
  • violated security property
  • attacker-controlled source and sensitive sink
  • concrete execution path
  • required preconditions and trust assumptions
  • impact
  • existing mitigation and why it is insufficient
  • smallest remediation that preserves Host and Node.js compatibility
  • regression test and validation status
  • Human review required: yes/no with the trigger

Use severity based on realistic impact and exploitability:

  • Critical: practical compromise across an intended isolation or control boundary with broad impact
  • High: practical code execution, credential disclosure, integrity loss, or reliable worker denial of service
  • Medium: constrained impact, strong preconditions, or meaningful defense-in-depth failure
  • Low: limited security impact or hardening with a plausible misuse path

If there are no evidence-backed findings, say so and list only residual assumptions or untested security boundaries. Do not inflate severity because a file is critical.

Repository-Specific Checks

  • Host messages: protobuf shape verification is not semantic validation. Check required relationships, sizes, one-of behavior, correlation IDs, and response/error handling.
  • Paths and loading: establish the intended app-root contract before requiring containment. Account for Windows and POSIX semantics and symlink behavior.
  • Environment reload: examine partial-failure behavior, rollback, dangerous process-wide changes, casing on Windows, and state left by the previous app.
  • Invocation: check typed-data conversions for lossy encoding, excessive allocation, prototype-sensitive keys, and confusion between user and system data.
  • Logs and errors: trace every Host-bound string. Sanitization must not leak the secret through stacks, URLs, structured objects, fallback logs, or hooks.
  • Availability: treat event-loop blocking, unlimited retries, message amplification, and hanging hooks as security issues only when less-trusted input can trigger material impact.
  • Dependencies: review runtime reachability, provenance, lockfile integrity, lifecycle scripts, transitive changes, and shipped bundle contents.

False-Positive Guardrails

  • Loading and executing the selected function application is the worker's purpose; it is not by itself arbitrary code execution.
  • CommonJS module caching and app-level hook persistence can be intentional within one function app.
  • grpc.credentials.createInsecure() for a Host-provided trusted localhost endpoint is an explicit compatibility mode, not automatically a vulnerability.
  • Host-controlled paths, metadata, and environment values are privileged inputs. A missing worker-side check can be hardening rather than an exploitable boundary bypass.
  • eval used only to preserve a dynamic import() through TypeScript compilation is not code injection unless untrusted text becomes executable syntax outside the intended module specifier.
  • Generated rpc.js, rpc_static.js, and rpc.d.ts should be reviewed against .proto source, not treated as independent hand-written flaws.

Any change that affects a listed trust boundary, executable-code selection, sanitization, process lifecycle, protocol compatibility, or runtime dependencies must also apply azure-functions-node-worker-critical-path and receive human review.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .github/skills/azure-functions-node-worker-security of Azure/azure-functions-nodejs-worker.

  • SKILL.md
  • references/threat-model.md

Open the folder on GitHubat commit 8c3b7f3

Compare with similar skills

Azure Functions Node Worker Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Functions Node Worker Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Functions Node Worker Security this skillAzure/azure-functions-nodejs-worker110—~2.4kAutomated safety check: PassMIT
Compileapache/skywalking-nodejs180—~1.3kAutomated safety check: PassApache-2.0
Fishjam JS Server SDKsoftware-mansion-labs/skills291—~1.4kAutomated safety check: PassMIT
Adding Personhog RpcPostHog/posthog-foss721—~2.1kAutomated safety check: PassMIT
Cortexdb Memory Openclawliliang-cn/cortexdb273—~1.6kAutomated safety check: PassMIT
Use Yaakmountain-loop/yaak19k—~1.9kAutomated safety check: PassMIT

Similar skills

  • Compile

    apache/skywalking-nodejs

    Compile / build / type-check the skywalking-nodejs agent. An agent skill from apache/skywalking-nodejs.

    180 GitHub stars~1.3k tokensUpdated 22 days ago
    Backend & APIsAuto-check passed
  • Fishjam JS Server SDK

    software-mansion-labs/skills

    Node.js / TypeScript server SDK for Fishjam — backends that create rooms, mint peer tokens, listen to server notifications, and run agents.

    291 GitHub stars~1.4k tokensUpdated 9 days ago
    Backend & APIsAuto-check passed
  • Adding Personhog Rpc

    PostHog/posthog-foss

    Official

    Guide for adding a new RPC to personhog-replica and personhog-router.

    721 GitHub stars~2.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Cortexdb Memory Openclaw

    liliang-cn/cortexdb

    Give a Node.js agent (such as OpenClaw) durable, local-first memory plus a queryable SPARQL knowledge graph, backed by CortexDB through its gRPC sidecar and the cortexdb-client npm package.

    273 GitHub stars~1.6k tokensUpdated today
    Knowledge ManagementAuto-check passed
  • Use Yaak

    mountain-loop/yaak

    A skill your agent uses when the user mentions Yaak, a Yaak workspace, or the yaak command, or asks to call, hit, or smoke test HTTP/REST endpoints, save or organize API requests for reuse or manual…

    19k GitHub stars~1.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Golang Pro

    antoniopaya22/go-rest-template

    Implements concurrent Go patterns using goroutines and channels, designs and builds microservices with gRPC or REST, optimizes Go application performance with pprof, and enforces idiomatic Go with…

    172 GitHub starsUsed in 3 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from Azure/azure-functions-nodejs-worker

  • Azure Functions Node Worker

    Azure/azure-functions-nodejs-worker

    Official

    Repository-specific Azure Functions Node.js Host-worker architecture and change-validation workflow.

    110 GitHub stars~2.1k tokensUpdated 4 days ago
    Auto-check passed
  • Azure Functions Node Worker Critical Path

    Azure/azure-functions-nodejs-worker

    Official

    Mandatory human-intervention gate for critical Azure Functions Node.js worker code.

    110 GitHub stars~2k tokensUpdated 4 days ago
    Auto-check passed

Categories

Questions about Azure Functions Node Worker Security

What does Azure Functions Node Worker Security do?

Security analysis for the Azure Functions Node.js worker. An agent skill from Azure/azure-functions-nodejs-worker. Azure Functions Node Worker Security is an agent skill from Azure/azure-functions-nodejs-worker, published by the product's own GitHub organization.js worker.

When should I use Azure Functions Node Worker Security?

Azure Functions Node Worker Security fits situations like: tasks that involve gRPC and Protobuf; tasks that involve Secrets management.

How do I install Azure Functions Node Worker Security in Claude Code?

Run `npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a claude-code`. Or copy the skill folder (.github/skills/azure-functions-node-worker-security in Azure/azure-functions-nodejs-worker) into .claude/skills/azure-functions-node-worker-security in your project. Claude Code loads it when a task matches its description.

How do I install Azure Functions Node Worker Security in Codex?

Run `npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a codex`. Or copy the skill folder (.github/skills/azure-functions-node-worker-security in Azure/azure-functions-nodejs-worker) into .agents/skills/azure-functions-node-worker-security in your project. Codex loads it when a task matches its description.

Can I use Azure Functions Node Worker Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/azure-functions-nodejs-worker --skill azure-functions-node-worker-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-functions-node-worker-security, .gemini/skills/azure-functions-node-worker-security, .github/skills/azure-functions-node-worker-security and .opencode/skills/azure-functions-node-worker-security in your project.

What does Azure Functions Node Worker Security need to run?

Going by SKILL.md and its folder, Azure Functions Node Worker Security needs the command-line tools its instructions call (npm and npx). Our summary lists: Node.js.

Does Azure Functions Node Worker Security access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Azure Functions Node Worker Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Functions Node Worker Security use?

Azure Functions Node Worker Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Functions Node Worker Security use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.

What are the alternatives to Azure Functions Node Worker Security?

Skills that share tags, products or a category with Azure Functions Node Worker Security: Compile (apache/skywalking-nodejs, 180 stars), Fishjam JS Server SDK (software-mansion-labs/skills, 291 stars), Adding Personhog Rpc (PostHog/posthog-foss, 721 stars) and Cortexdb Memory Openclaw (liliang-cn/cortexdb, 273 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Functions Node Worker Security?

Azure (a GitHub organization, an official publisher) maintains it in Azure/azure-functions-nodejs-worker, which has 110 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 3, 2026.

Source: Azure/azure-functions-nodejs-worker on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.