Agent skill

Typescript Security Review

by giuseppe-trisciuoglio in giuseppe-trisciuoglio/developer-kit

Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure.

MITAuto-check: notesSecurity

Install Typescript Security Review

skills CLI
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install giuseppe-trisciuoglio/developer-kit typescript-security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/typescript-security-review .claude/skills/typescript-security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
typescript-security-review
GitHub stars
357
Token cost
~2.4k tokens
SKILL.md length
845 words
Files
7 (incl. references)
Skills in repo
115
Repo updated
First seen
Licence
MIT

At a glance

Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure.

  • Works in 7 steps: Security Posture Summary → Critical Vulnerabilities (Immediate… → High Priority (Address Within 30 Days) → …
  • Performing security audits
  • SKILL.md covers Overview, When to Use, Instructions and Examples, plus 4 more sections
  • Calls npm; needs JWT_SECRET

What it does

Typescript Security Review is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. Use when performing security audits, before deployment, reviewing authentication/authorization implementations, or ensuring OWASP compliance for Express, NestJS, and Next.js. Triggers on "security review", "check for security issues", "TypeScript security audit".

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/common-vulnerabilities.md`, `references/dependency-security.md` and `references/input-validation.md`).

It sits in Security, covering Security review, Web application vulnerabilities and Authentication. It works with TypeScript, Node.js, NestJS and Next.js. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.

When your agent uses it

  • Performing security audits
  • Before deployment
  • Reviewing authentication/authorization implementations
  • Ensuring OWASP compliance for Express

Example prompts

  • “security review”
  • “check for security issues”
  • “TypeScript security audit”
  • “/typescript-security-review”

Requirements

  • Node.js
  • A credential in JWT_SECRET
  • Pre-approved tools (allowed-tools): Read, Edit, Grep, Glob, Bash

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Security Posture Summary
  2. Critical Vulnerabilities (Immediate Action)
  3. High Priority (Address Within 30 Days)
  4. Medium Priority (Address Within 90 Days)
  5. Low Priority (Next Cycle)
  6. Positive Security Observations
  7. Remediation Roadmap

What it can do on your machine

Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Edit
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Typescript Security Review loads about 2.4k tokens when it runs, and up to ~8.7k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 845 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:48
    PI keys, secrets in source code. Verify `.env` files are gitignored, secrets accessed through proper management services
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Edit, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 845 words, ~2,385 tokens.

Download SKILL.mdSave it as .claude/skills/typescript-security-review/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
typescript-security-review
description
Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. Use when performing security audits, before deployment, reviewing authentication/authorization implementations, or ensuring OWASP compliance for Express, NestJS, and Next.js. Triggers on "security review", "check for security issues", "TypeScript security audit".
allowed-tools
Read, Edit, Grep, Glob, Bash

TypeScript Security Review

Overview

Security review for TypeScript/Node.js applications. Evaluates code against OWASP Top 10, framework-specific patterns, and production-readiness criteria. Findings are classified by severity (Critical, High, Medium, Low) with remediation examples. Delegates to the typescript-security-expert agent for deep analysis.

When to Use

  • Performing security audits on TypeScript/Node.js codebases
  • Reviewing authentication and authorization implementations (JWT, OAuth2, Passport.js)
  • Checking for common vulnerabilities (XSS, injection, CSRF, path traversal)
  • Validating input validation and sanitization logic
  • Reviewing dependency security (npm audit, known CVEs)
  • Checking secrets management and environment variable handling
  • Assessing API security (rate limiting, CORS, security headers)
  • Reviewing Express, NestJS, or Next.js security configurations
  • Before deploying to production or after significant code changes
  • Compliance checks (GDPR, HIPAA, SOC2 data handling requirements)

Instructions

  1. Identify Scope: Determine which files and modules are under review. Prioritize authentication, authorization, data handling, API endpoints, and configuration files. Use grep to find security-sensitive patterns (eval, exec, innerHTML, password handling, JWT operations).

    Checkpoint: Verify at least 3 security-sensitive files/modules identified before proceeding.

  2. Check Authentication & Authorization: Review JWT implementation (signing algorithm, expiration, refresh tokens), OAuth2/OIDC integration, session management, password hashing (bcrypt/argon2), and multi-factor authentication. Verify protected routes enforce authentication.

    Checkpoint: Use grep to confirm all route handlers have auth guards or middleware applied.

  3. Scan for Injection Vulnerabilities: Check for SQL/NoSQL injection in database queries, command injection in exec/spawn, template injection, and LDAP injection. Verify parameterized queries and input validation.

    Checkpoint: Use grep to confirm all database queries use parameterization — no string concatenation with user input.

  4. Review Input Validation: Check API inputs validated with Zod, Joi, or class-validator. Verify schema completeness — proper type constraints, length limits, format validation. Check for validation bypass paths.

    Checkpoint: Verify all public API endpoints have corresponding validation schemas.

  5. Assess XSS Prevention: Review React components for dangerouslySetInnerHTML usage, check Content Security Policy headers, verify HTML sanitization for user-generated content. See references/xss-prevention.md for detailed patterns.

    Checkpoint: Use grep to confirm any dangerouslySetInnerHTML usage has sanitization via DOMPurify or equivalent.

  6. Check Secrets Management: Scan for hardcoded credentials, API keys, secrets in source code. Verify .env files are gitignored, secrets accessed through proper management services.

    Checkpoint: Run grep -r "password\|secret\|api.*key\|token" --include="*.ts" to identify potential secrets in code.

  7. Review Dependency Security: Run npm audit or check package-lock.json for known vulnerabilities. Identify outdated dependencies with CVEs. Check for unnecessary dependencies.

    Checkpoint: Verify npm audit results are reviewed and critical vulnerabilities addressed.

  8. Evaluate Security Headers & Configuration: Check helmet.js or manual security header configuration. Review CORS policy, rate limiting, HTTPS enforcement, cookie security flags (HttpOnly, Secure, SameSite), and CSP. See references/security-headers.md for configuration examples.

    Checkpoint: Use grep to confirm helmet or equivalent security headers are applied globally.

  9. Produce Security Report: Generate structured report with severity-classified findings, remediation guidance with code examples, and security posture summary.

    Feedback Loop: If Critical or High vulnerabilities found, re-scan related modules for similar patterns before finalizing. Use grep to identify if the same vulnerability pattern exists elsewhere.

Examples

JWT Security Review
typescript
// ❌ Critical: Weak JWT configuration
import jwt from 'jsonwebtoken';

const SECRET = 'mysecret123'; // Hardcoded weak secret

function generateToken(user: User) {
  return jwt.sign({ id: user.id, role: user.role }, SECRET);
  // Missing expiration, weak secret, no algorithm specification
}

// ✅ Secure: Proper JWT configuration
import jwt from 'jsonwebtoken';

const JWT_SECRET = process.env.JWT_SECRET;
if (!JWT_SECRET || JWT_SECRET.length < 32) {
  throw new Error('JWT_SECRET must be set and at least 32 characters');
}

function generateToken(user: User): string {
  return jwt.sign(
    { sub: user.id }, // Minimal claims, no sensitive data
    JWT_SECRET,
    {
      algorithm: 'HS256',
      expiresIn: '15m',
      issuer: 'my-app',
      audience: 'my-app-client',
    }
  );
}

function verifyToken(token: string): JwtPayload {
  return jwt.verify(token, JWT_SECRET, {
    algorithms: ['HS256'], // Restrict accepted algorithms
    issuer: 'my-app',
    audience: 'my-app-client',
  }) as JwtPayload;
}
SQL Injection Prevention
typescript
// ❌ Critical: SQL injection vulnerability
async function findUser(email: string) {
  const result = await db.query(
    `SELECT * FROM users WHERE email = '${email}'`
  );
  return result.rows[0];
}

// ✅ Secure: Parameterized query
async function findUser(email: string) {
  const result = await db.query(
    'SELECT id, name, email FROM users WHERE email = $1',
    [email]
  );
  return result.rows[0];
}

// ✅ Secure: ORM with type-safe queries (Drizzle example)
async function findUser(email: string) {
  return db.select({
    id: users.id,
    name: users.name,
    email: users.email,
  })
  .from(users)
  .where(eq(users.email, email))
  .limit(1);
}

See references/xss-prevention.md for XSS patterns and references/security-headers.md for security headers configuration.

Show full SKILL.md (341 more words)Show less

Review Output Format

Structure all security review findings as follows:

1. Security Posture Summary

Overall security assessment score (1-10) with key observations and risk level.

2. Critical Vulnerabilities (Immediate Action)

Issues that can be exploited to compromise the system, steal data, or cause unauthorized access.

3. High Priority (Address Within 30 Days)

Security misconfigurations, missing protections, or vulnerabilities requiring near-term remediation.

4. Medium Priority (Address Within 90 Days)

Issues that reduce security posture but have mitigating factors or limited exploitability.

5. Low Priority (Next Cycle)

Security improvements, hardening recommendations, and defense-in-depth enhancements.

6. Positive Security Observations

Well-implemented security patterns and practices to acknowledge.

7. Remediation Roadmap

Prioritized action items with code examples for the most critical fixes.

Best Practices

  • Validate all inputs at the API boundary — never trust client-side validation alone
  • Use parameterized queries or ORMs — never concatenate user input into queries
  • Store secrets in environment variables or secret managers — never in source code
  • Apply the principle of least privilege for database accounts, API keys, and IAM roles
  • Enable security headers (helmet.js) and restrict CORS to known origins
  • Implement rate limiting on all public-facing endpoints
  • Hash passwords with bcrypt or argon2 — never use MD5/SHA for passwords
  • Set cookie flags: HttpOnly, Secure, SameSite=Strict
  • Use npm audit in CI pipelines to catch dependency vulnerabilities
  • Log security events (failed logins, permission denials) without logging sensitive data

Constraints and Warnings

  • Security review is not a substitute for professional penetration testing
  • Focus on code-level vulnerabilities — infrastructure security is out of scope
  • Respect the project's framework — provide framework-specific remediation guidance
  • Do not log, print, or expose discovered secrets — report their location only
  • Dependency vulnerabilities should be assessed for actual exploitability, not just presence
  • Security recommendations must be practical — consider implementation effort vs risk reduction

References

See the references/ directory for detailed security documentation:

  • references/owasp-typescript.md — OWASP Top 10 mapped to TypeScript/Node.js patterns
  • references/common-vulnerabilities.md — Common vulnerability patterns and remediation
  • references/dependency-security.md — Dependency scanning and supply chain security
  • references/xss-prevention.md — XSS prevention patterns for React and server-side
  • references/security-headers.md — Security headers and CORS configuration examples
  • references/input-validation.md — Input validation patterns with Zod and class-validator

© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in plugins/developer-kit-typescript/skills/typescript-security-review of giuseppe-trisciuoglio/developer-kit.

  • SKILL.md
  • references/common-vulnerabilities.md
  • references/dependency-security.md
  • references/input-validation.md
  • references/owasp-typescript.md
  • references/security-headers.md
  • references/xss-prevention.md

Open the folder on GitHubat commit fe73fb3

Compare with similar skills

Typescript Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Typescript Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Typescript Security Review this skillgiuseppe-trisciuoglio/developer-kit357—~2.4kAutomated safety check: NotesMIT
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT
Owasp Security AuditLIDR-academy/AI4Devs-LTI-extended278—~4.3kAutomated safety check: NotesMIT
Security Reviewdeadlock-mod-manager/deadlock-mod-manager478—~1.8kAutomated safety check: PassCC-BY-SA-4.0
Security Auditjellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMIT
Security Practiceseser/stack128—~598Automated safety check: PassCustom licence

Similar skills

  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Owasp Security Audit

    LIDR-academy/AI4Devs-LTI-extended

    A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a…

    278 GitHub stars~4.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Security Review

    deadlock-mod-manager/deadlock-mod-manager

    Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.

    478 GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies…

    128 GitHub stars~598 tokensUpdated 7 days ago
    SecurityAuto-check passed
  • Security

    serithemage/serverless-openclaw

    References Serverless OpenClaw security model. An agent skill from serithemage/serverless-openclaw.

    196 GitHub stars~633 tokensUpdated 6 mo ago
    SecurityAuto-check passed

More from giuseppe-trisciuoglio/developer-kit

All 115 skills in this repo
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    357 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Actuator

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

    357 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Crud Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides and generates complete CRUD workflows for Spring Boot 3 services.

    357 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    357 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • PR Review Comments

    giuseppe-trisciuoglio/developer-kit

    Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

    357 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check: notes

Categories

Questions about Typescript Security Review

What does Typescript Security Review do?

Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. Typescript Security Review is an agent skill from giuseppe-trisciuoglio/developer-kit.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure.

When should I use Typescript Security Review?

Typescript Security Review fits situations like: performing security audits; before deployment; reviewing authentication/authorization implementations; ensuring OWASP compliance for Express.

How do I install Typescript Security Review in Claude Code?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a claude-code`. Or copy the skill folder (plugins/developer-kit-typescript/skills/typescript-security-review in giuseppe-trisciuoglio/developer-kit) into .claude/skills/typescript-security-review in your project. Claude Code loads it when a task matches its description.

How do I install Typescript Security Review in Codex?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a codex`. Or copy the skill folder (plugins/developer-kit-typescript/skills/typescript-security-review in giuseppe-trisciuoglio/developer-kit) into .agents/skills/typescript-security-review in your project. Codex loads it when a task matches its description.

Can I use Typescript Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/typescript-security-review, .gemini/skills/typescript-security-review, .github/skills/typescript-security-review and .opencode/skills/typescript-security-review in your project.

What does Typescript Security Review need to run?

Going by SKILL.md and its folder, Typescript Security Review needs the command-line tools its instructions call (npm) and credentials named JWT_SECRET. Our summary lists: Node.js; A credential in JWT_SECRET. Its frontmatter pre-approves these tools: Read, Edit, Grep, Glob, Bash.

Does Typescript Security Review access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Typescript Security Review safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Typescript Security Review use?

Typescript Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Typescript Security Review use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.3k tokens, read only when the agent opens those files.

What are the alternatives to Typescript Security Review?

Skills that share tags, products or a category with Typescript Security Review: Security Review (jewbetcha/opentrace, 116 stars), Owasp Security Audit (LIDR-academy/AI4Devs-LTI-extended, 278 stars), Security Review (deadlock-mod-manager/deadlock-mod-manager, 478 stars) and Security Audit (jellydn/my-ai-tools, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Typescript Security Review?

giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.

Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.