Security Review
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
Agent skill
by giuseppe-trisciuoglio in giuseppe-trisciuoglio/developer-kit
Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit typescript-security-review --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/typescript-security-review .claude/skills/typescript-security-review && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "typescript-security-review" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/typescript-security-review into .claude/skills/typescript-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "typescript-security-review", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/typescript-security-reviewType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit typescript-security-review --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/typescript-security-review .agents/skills/typescript-security-review && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "typescript-security-review" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/typescript-security-review into .agents/skills/typescript-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "typescript-security-review", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit typescript-security-review --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/typescript-security-review .cursor/skills/typescript-security-review && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "typescript-security-review" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/typescript-security-review into .cursor/skills/typescript-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "typescript-security-review", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/giuseppe-trisciuoglio/developer-kit.git --path plugins/developer-kit-typescript/skills/typescript-security-review--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit typescript-security-review --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/typescript-security-review .gemini/skills/typescript-security-review && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "typescript-security-review" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/typescript-security-review into .gemini/skills/typescript-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "typescript-security-review", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install giuseppe-trisciuoglio/developer-kit typescript-security-reviewInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/typescript-security-review .github/skills/typescript-security-review && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "typescript-security-review" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/typescript-security-review into .github/skills/typescript-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "typescript-security-review", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install giuseppe-trisciuoglio/developer-kit typescript-security-review --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/developer-kit-typescript/skills/typescript-security-review .opencode/skills/typescript-security-review && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "typescript-security-review" agent skill from https://github.com/giuseppe-trisciuoglio/developer-kit/tree/main/plugins/developer-kit-typescript/skills/typescript-security-review into .opencode/skills/typescript-security-review/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "typescript-security-review", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
typescript-security-reviewProvides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure.
Typescript Security Review is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. Use when performing security audits, before deployment, reviewing authentication/authorization implementations, or ensuring OWASP compliance for Express, NestJS, and Next.js. Triggers on "security review", "check for security issues", "TypeScript security audit".
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/common-vulnerabilities.md`, `references/dependency-security.md` and `references/input-validation.md`).
It sits in Security, covering Security review, Web application vulnerabilities and Authentication. It works with TypeScript, Node.js, NestJS and Next.js. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadEditGrepGlobBashFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
JWT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Typescript Security Review loads about 2.4k tokens when it runs, and up to ~8.7k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 845 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
PI keys, secrets in source code. Verify `.env` files are gitignored, secrets accessed through proper management servicesallowed-tools: Read, Edit, Grep, Glob, BashAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 845 words, ~2,385 tokens.
.claude/skills/typescript-security-review/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Security review for TypeScript/Node.js applications. Evaluates code against OWASP Top 10, framework-specific patterns, and production-readiness criteria. Findings are classified by severity (Critical, High, Medium, Low) with remediation examples. Delegates to the typescript-security-expert agent for deep analysis.
Identify Scope: Determine which files and modules are under review. Prioritize authentication, authorization, data handling, API endpoints, and configuration files. Use grep to find security-sensitive patterns (eval, exec, innerHTML, password handling, JWT operations).
Checkpoint: Verify at least 3 security-sensitive files/modules identified before proceeding.
Check Authentication & Authorization: Review JWT implementation (signing algorithm, expiration, refresh tokens), OAuth2/OIDC integration, session management, password hashing (bcrypt/argon2), and multi-factor authentication. Verify protected routes enforce authentication.
Checkpoint: Use grep to confirm all route handlers have auth guards or middleware applied.
Scan for Injection Vulnerabilities: Check for SQL/NoSQL injection in database queries, command injection in exec/spawn, template injection, and LDAP injection. Verify parameterized queries and input validation.
Checkpoint: Use grep to confirm all database queries use parameterization — no string concatenation with user input.
Review Input Validation: Check API inputs validated with Zod, Joi, or class-validator. Verify schema completeness — proper type constraints, length limits, format validation. Check for validation bypass paths.
Checkpoint: Verify all public API endpoints have corresponding validation schemas.
Assess XSS Prevention: Review React components for dangerouslySetInnerHTML usage, check Content Security Policy headers, verify HTML sanitization for user-generated content. See references/xss-prevention.md for detailed patterns.
Checkpoint: Use grep to confirm any dangerouslySetInnerHTML usage has sanitization via DOMPurify or equivalent.
Check Secrets Management: Scan for hardcoded credentials, API keys, secrets in source code. Verify .env files are gitignored, secrets accessed through proper management services.
Checkpoint: Run grep -r "password\|secret\|api.*key\|token" --include="*.ts" to identify potential secrets in code.
Review Dependency Security: Run npm audit or check package-lock.json for known vulnerabilities. Identify outdated dependencies with CVEs. Check for unnecessary dependencies.
Checkpoint: Verify npm audit results are reviewed and critical vulnerabilities addressed.
Evaluate Security Headers & Configuration: Check helmet.js or manual security header configuration. Review CORS policy, rate limiting, HTTPS enforcement, cookie security flags (HttpOnly, Secure, SameSite), and CSP. See references/security-headers.md for configuration examples.
Checkpoint: Use grep to confirm helmet or equivalent security headers are applied globally.
Produce Security Report: Generate structured report with severity-classified findings, remediation guidance with code examples, and security posture summary.
Feedback Loop: If Critical or High vulnerabilities found, re-scan related modules for similar patterns before finalizing. Use grep to identify if the same vulnerability pattern exists elsewhere.
// ❌ Critical: Weak JWT configuration
import jwt from 'jsonwebtoken';
const SECRET = 'mysecret123'; // Hardcoded weak secret
function generateToken(user: User) {
return jwt.sign({ id: user.id, role: user.role }, SECRET);
// Missing expiration, weak secret, no algorithm specification
}
// ✅ Secure: Proper JWT configuration
import jwt from 'jsonwebtoken';
const JWT_SECRET = process.env.JWT_SECRET;
if (!JWT_SECRET || JWT_SECRET.length < 32) {
throw new Error('JWT_SECRET must be set and at least 32 characters');
}
function generateToken(user: User): string {
return jwt.sign(
{ sub: user.id }, // Minimal claims, no sensitive data
JWT_SECRET,
{
algorithm: 'HS256',
expiresIn: '15m',
issuer: 'my-app',
audience: 'my-app-client',
}
);
}
function verifyToken(token: string): JwtPayload {
return jwt.verify(token, JWT_SECRET, {
algorithms: ['HS256'], // Restrict accepted algorithms
issuer: 'my-app',
audience: 'my-app-client',
}) as JwtPayload;
}// ❌ Critical: SQL injection vulnerability
async function findUser(email: string) {
const result = await db.query(
`SELECT * FROM users WHERE email = '${email}'`
);
return result.rows[0];
}
// ✅ Secure: Parameterized query
async function findUser(email: string) {
const result = await db.query(
'SELECT id, name, email FROM users WHERE email = $1',
[email]
);
return result.rows[0];
}
// ✅ Secure: ORM with type-safe queries (Drizzle example)
async function findUser(email: string) {
return db.select({
id: users.id,
name: users.name,
email: users.email,
})
.from(users)
.where(eq(users.email, email))
.limit(1);
}See references/xss-prevention.md for XSS patterns and references/security-headers.md for security headers configuration.
Structure all security review findings as follows:
Overall security assessment score (1-10) with key observations and risk level.
Issues that can be exploited to compromise the system, steal data, or cause unauthorized access.
Security misconfigurations, missing protections, or vulnerabilities requiring near-term remediation.
Issues that reduce security posture but have mitigating factors or limited exploitability.
Security improvements, hardening recommendations, and defense-in-depth enhancements.
Well-implemented security patterns and practices to acknowledge.
Prioritized action items with code examples for the most critical fixes.
HttpOnly, Secure, SameSite=Strictnpm audit in CI pipelines to catch dependency vulnerabilitiesSee the references/ directory for detailed security documentation:
references/owasp-typescript.md — OWASP Top 10 mapped to TypeScript/Node.js patternsreferences/common-vulnerabilities.md — Common vulnerability patterns and remediationreferences/dependency-security.md — Dependency scanning and supply chain securityreferences/xss-prevention.md — XSS prevention patterns for React and server-sidereferences/security-headers.md — Security headers and CORS configuration examplesreferences/input-validation.md — Input validation patterns with Zod and class-validator© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in plugins/developer-kit-typescript/skills/typescript-security-review of giuseppe-trisciuoglio/developer-kit.
Open the folder on GitHubat commit fe73fb3
Typescript Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Typescript Security Review this skillgiuseppe-trisciuoglio/developer-kit | 357 | — | ~2.4k | Automated safety check: Notes | MIT | |
| Security Reviewjewbetcha/opentrace | 116 | 18 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Owasp Security AuditLIDR-academy/AI4Devs-LTI-extended | 278 | — | ~4.3k | Automated safety check: Notes | MIT | |
| Security Reviewdeadlock-mod-manager/deadlock-mod-manager | 478 | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Security Auditjellydn/my-ai-tools | 123 | — | ~2.9k | Automated safety check: Notes | MIT | |
| Security Practiceseser/stack | 128 | — | ~598 | Automated safety check: Pass | Custom licence |
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
LIDR-academy/AI4Devs-LTI-extended
A skill your agent uses when performing a cybersecurity audit, security review, OWASP Top 10 compliance check, vulnerability assessment, or preparing for a penetration test on a…
deadlock-mod-manager/deadlock-mod-manager
Security code review for Tauri/Rust/TypeScript desktop apps and Hono/oRPC APIs.
jellydn/my-ai-tools
A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.
eser/stack
Security rules for eserstack in TypeScript and Go: secrets, output hygiene, input validation, authorization, injection, SSRF, error sanitization, httpfx hardening, tokens, passwords, cookies…
serithemage/serverless-openclaw
References Serverless OpenClaw security model. An agent skill from serithemage/serverless-openclaw.
giuseppe-trisciuoglio/developer-kit
Generates complete CRUD modules for NestJS applications with Drizzle ORM.
giuseppe-trisciuoglio/developer-kit
Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.
giuseppe-trisciuoglio/developer-kit
Provides and generates complete CRUD workflows for Spring Boot 3 services.
giuseppe-trisciuoglio/developer-kit
Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…
giuseppe-trisciuoglio/developer-kit
Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.
giuseppe-trisciuoglio/developer-kit
Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.
Works with
Categories
Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. Typescript Security Review is an agent skill from giuseppe-trisciuoglio/developer-kit.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure.
Typescript Security Review fits situations like: performing security audits; before deployment; reviewing authentication/authorization implementations; ensuring OWASP compliance for Express.
Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a claude-code`. Or copy the skill folder (plugins/developer-kit-typescript/skills/typescript-security-review in giuseppe-trisciuoglio/developer-kit) into .claude/skills/typescript-security-review in your project. Claude Code loads it when a task matches its description.
Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a codex`. Or copy the skill folder (plugins/developer-kit-typescript/skills/typescript-security-review in giuseppe-trisciuoglio/developer-kit) into .agents/skills/typescript-security-review in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill typescript-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/typescript-security-review, .gemini/skills/typescript-security-review, .github/skills/typescript-security-review and .opencode/skills/typescript-security-review in your project.
Going by SKILL.md and its folder, Typescript Security Review needs the command-line tools its instructions call (npm) and credentials named JWT_SECRET. Our summary lists: Node.js; A credential in JWT_SECRET. Its frontmatter pre-approves these tools: Read, Edit, Grep, Glob, Bash.
SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Typescript Security Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Typescript Security Review: Security Review (jewbetcha/opentrace, 116 stars), Owasp Security Audit (LIDR-academy/AI4Devs-LTI-extended, 278 stars), Security Review (deadlock-mod-manager/deadlock-mod-manager, 478 stars) and Security Audit (jellydn/my-ai-tools, 123 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.
Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.