Agent skill

JS Security Audit

by c0x12c in c0x12c/ai-toolkit

Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.

No licenceAuto-check: warningsSecurity

Install JS Security Audit

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add c0x12c/ai-toolkit --skill js-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install c0x12c/ai-toolkit js-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/c0x12c/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/toolkit/skills/js-security-audit .claude/skills/js-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
js-security-audit
GitHub stars
106
Token cost
~1.6k tokens
SKILL.md length
599 words
Files
5
Skills in repo
33
Repo updated
First seen
Licence
None found

At a glance

Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.

  • Works in 5 steps: Project Setup → Dependency Hygiene → CI/CD Pipeline → …
  • Reviewing package.json
  • SKILL.md covers When to Use, Process, Interaction Style and Rules, plus 3 more sections
  • Calls npm

What it does

JS Security Audit is an agent skill from c0x12c/ai-toolkit. Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response. Use when reviewing package.json or lockfiles, adding or upgrading npm dependencies, setting up CI security gates, hardening a new repo, or responding to a compromised package.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `audit-checklist.md`, `eslint-security.md` and `incident-playbook.md`).

It sits in Security, covering Dependency management, Security review and Incident response. It works with npm, pnpm and ESLint.

When your agent uses it

  • Reviewing package.json
  • Upgrading npm dependencies
  • Setting up CI security gates
  • Hardening a new repo

Example prompts

  • “/js-security-audit”

Requirements

  • Node.js

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Project Setup
  2. Dependency Hygiene
  3. CI/CD Pipeline
  4. Dependabot
  5. Incident Response Readiness

What it can do on your machine

Read from SKILL.md and the folder at commit 96b2c9d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

JS Security Audit loads about 1.6k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 599 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:17
    - New repo hardening — verify `.npmrc`, lockfiles, 2FA, exact pinning
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:33
    Check `.npmrc`, lockfile presence, version pinning, `.gitignore`, scoped packages.
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:58
    - **Warning** — missing `.npmrc` hardening, no Dependabot config, no SBOM generation, ESLint security config missing
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:123
    - **[Project Setup]** `.npmrc` missing `ignore-scripts=true`
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:124
    - File: `.npmrc:1`

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 599 words (~1,590 tokens).

“Run a 5-area security audit on a JS/TS project (npm, yarn, or pnpm). Produces a pass/fail report per area with file:line references.”

— opening of SKILL.md by c0x12c
name
js-security-audit

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files in toolkit/skills/js-security-audit of c0x12c/ai-toolkit.

  • SKILL.md
  • audit-checklist.md
  • eslint-security.md
  • incident-playbook.md
  • package-manager.md

Open the folder on GitHubat commit 96b2c9d

Compare with similar skills

JS Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

JS Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
JS Security Audit this skillc0x12c/ai-toolkit106—~1.6kAutomated safety check: WarnNone
Check Deps SyncHyk260/PureChat546—~594Automated safety check: PassMIT
Uv WorkflowAedelon/claude-code-blueprint120—~1.2kAutomated safety check: NotesCustom licence
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Audit And Reduce Dependenciesgrafana/skills281—~3.6kAutomated safety check: WarnApache-2.0
npm Supply Chain Securitybodadotsh/npm-security-best-practices858—~1kAutomated safety check: WarnMIT

Similar skills

  • Check Deps Sync

    Hyk260/PureChat

    Check if package.json files are in sync with pnpm-lock.yaml.

    546 GitHub stars~594 tokensUpdated 22 days ago
    DevOps & CloudAuto-check passed
  • Uv Workflow

    Aedelon/claude-code-blueprint

    Master uv package manager for Python: project setup, dependency management, virtual environments, lockfiles, CI/CD integration, Docker builds, and migration from pip/poetry.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Official

    Reduces JavaScript dependency footprint with pnpm while preserving lockfile, workspace layout, and dependency range style.

    281 GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check: warnings
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    858 GitHub stars~1k tokensUpdated 8 days ago
    SecurityAuto-check: warnings
  • Fix Vulns

    linuxfoundation/insights

    Automated triage and fixing of Dependabot security vulnerabilities (IN-1189).

    280 GitHub stars~3.8k tokensUpdated 7 days ago
    SecurityAuto-check: notes

More from c0x12c/ai-toolkit

All 33 skills in this repo
  • UI UX Pro Max

    c0x12c/ai-toolkit

    UI/UX design intelligence with searchable style, palette, typography, and chart databases.

    106 GitHub stars~2.1k tokensUpdated 3 mo ago
    Auto-check passed
  • API Endpoint Creator

    c0x12c/ai-toolkit

    Creates RPC-style endpoint following layered architecture (Controller → Manager → Repository).

    106 GitHub stars~3.3k tokensUpdated 3 mo ago
    Auto-check passed
  • Backend API Design

    c0x12c/ai-toolkit

    Design RPC-style APIs with layered architecture (Controller → Manager → Repository).

    106 GitHub stars~814 tokensUpdated 3 mo ago
    Auto-check passed
  • CI CD Patterns

    c0x12c/ai-toolkit

    CI/CD pipeline patterns for GitHub Actions, PR automation, and deployment workflows.

    106 GitHub stars~833 tokensUpdated 3 mo ago
    Auto-check passed
  • Content Engine

    c0x12c/ai-toolkit

    Turn one idea into platform-native content for X, LinkedIn, TikTok, YouTube, newsletters.

    106 GitHub stars~986 tokensUpdated 3 mo ago
    Auto-check passed
  • Database Table Creator

    c0x12c/ai-toolkit

    Creates database table with full Kotlin synchronization (SQL migration → Table → Entity → Repository → Tests).

    106 GitHub stars~1.1k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Questions about JS Security Audit

What does JS Security Audit do?

Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response. JS Security Audit is an agent skill from c0x12c/ai-toolkit. Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.

When should I use JS Security Audit?

JS Security Audit fits situations like: reviewing package.json; upgrading npm dependencies; setting up CI security gates; hardening a new repo.

How do I install JS Security Audit in Claude Code?

Run `npx skills add c0x12c/ai-toolkit --skill js-security-audit -a claude-code`. Or copy the skill folder (toolkit/skills/js-security-audit in c0x12c/ai-toolkit) into .claude/skills/js-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install JS Security Audit in Codex?

Run `npx skills add c0x12c/ai-toolkit --skill js-security-audit -a codex`. Or copy the skill folder (toolkit/skills/js-security-audit in c0x12c/ai-toolkit) into .agents/skills/js-security-audit in your project. Codex loads it when a task matches its description.

Can I use JS Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add c0x12c/ai-toolkit --skill js-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/js-security-audit, .gemini/skills/js-security-audit, .github/skills/js-security-audit and .opencode/skills/js-security-audit in your project.

What does JS Security Audit need to run?

Going by SKILL.md and its folder, JS Security Audit needs the command-line tools its instructions call (npm). Our summary lists: Node.js.

Does JS Security Audit access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is JS Security Audit safe to install?

Our automated static check of SKILL.md flagged 5 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does JS Security Audit use?

No licence was found for JS Security Audit or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does JS Security Audit use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to JS Security Audit?

Skills that share tags, products or a category with JS Security Audit: Check Deps Sync (Hyk260/PureChat, 546 stars), Uv Workflow (Aedelon/claude-code-blueprint, 120 stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars) and Audit And Reduce Dependencies (grafana/skills, 281 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains JS Security Audit?

c0x12c (a GitHub organization) maintains it in c0x12c/ai-toolkit, which has 106 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on June 18, 2026.

Source: c0x12c/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.