Agent skill

Typescript Security

by HoangNguyen0403 in HoangNguyen0403/agent-skills-standard

Secure server-side TypeScript input, auth tokens, and injection boundaries.

MITAuto-check: notesDevelopment

Install Typescript Security

skills CLI
$ npx skills add HoangNguyen0403/agent-skills-standard --skill typescript-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install HoangNguyen0403/agent-skills-standard typescript-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/HoangNguyen0403/agent-skills-standard.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/typescript/typescript-security .claude/skills/typescript-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
typescript-security
GitHub stars
572
Token cost
~817 tokens
SKILL.md length
319 words
Files
3 (incl. references)
Skills in repo
211
Repo updated
First seen
Licence
MIT

At a glance

Secure server-side TypeScript input, auth tokens, and injection boundaries.

  • API/request validation
  • SKILL.md covers Priority: P0 (CRITICAL), Validate Input at Boundaries, Prevent Injection and XSS and Secure Authentication, plus 4 more sections
  • Needs JWT_SECRET
  • Sensitive configuration

What it does

Typescript Security is an agent skill from HoangNguyen0403/agent-skills-standard. Secure server-side TypeScript input, auth tokens, and injection boundaries. Use for API/request validation, sanitization, secrets, and sensitive configuration; defer client-only React form validation and generic linting.

Its SKILL.md is about 820 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `evals/evals.json` and `references/REFERENCE.md`).

It sits in Development, covering Forms and validation, Linting and formatting and Backend development. It works with TypeScript, React and Zod. The repository describes itself as: A collection of Agent Skills Standard and Best Practice for Programming Languages, Frameworks that help our AI Agent follow best practies on frameworks and programming laguages. The licence is MIT.

When your agent uses it

  • API/request validation
  • Sensitive configuration
  • Defer client-only React form validation and generic linting

Example prompts

  • “/typescript-security”

Requirements

  • Node.js
  • A credential in JWT_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit b529c2d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Typescript Security loads about 817 tokens when it runs, and up to ~1.7k if it reads all its reference files. Until then it costs about 60 tokens; SKILL.md has 319 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~817
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:38
    - **Secrets**: Store secrets in **`.env`** (e.g., **`JWT_SECRET`**) or **Secret Managers**. NEVER commit them to Git.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from HoangNguyen0403/agent-skills-standard at commit b529c2d, republished under its MIT licence (© HoangNguyen0403). 319 words, ~817 tokens.

Download SKILL.mdSave it as .claude/skills/typescript-security/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
typescript-security
description
Secure server-side TypeScript input, auth tokens, and injection boundaries. Use for API/request validation, sanitization, secrets, and sensitive configuration; defer client-only React form validation and generic linting.

TypeScript Security

Priority: P0 (CRITICAL)

Validate Input at Boundaries

  • Use Zod, Joi, or class-validator at API boundary. Always parse and validate user-controlled input before using. Use safeParse for error handling without throwing. Return 400 with structured errors on failure.

See references/REFERENCE.md for Zod validation schemas, secure cookie setup, and JWT auth patterns.

Prevent Injection and XSS

  • Sanitization: Use DOMPurify for HTML sanitization to prevent Cross-Site Scripting (XSS).
  • SQL Injection: Use Parameterized Queries (e.g., pool.query('... WHERE id = $1', [id])) or Type-safe ORMs (Prisma/TypeORM). Use Prisma.sql for raw queries.
  • Input Filtering: Sanitize user-controlled input before using it in file paths or OS commands (Command Injection).

Secure Authentication

  • Use Argon2id for password hashing. Implement JWT (via jsonwebtoken or jose) with HttpOnly and Secure cookies. Use RS256 for public/private key pairs and implement Refresh Token rotation.
  • Secrets: Store secrets in .env (e.g., JWT_SECRET) or Secret Managers. NEVER commit them to Git.
  • CORS: Configure CORS with Strict Origin Whitelisting. Avoid origin: '*'.
  • Encryption: Use crypto (Node.js) or Web Crypto API for sensitive data. Avoid legacy algorithms like MD5/SHA1.

Verification

After typing validation schemas (Zod/joi) or auth guards, call getDiagnostics (typescript-lsp) to confirm type narrowing correct before finalizing.

Anti-Patterns

  • No dynamic execution: Avoid eval, Function constructor, or string literals as timer callbacks — all execute runtime code and bypass TypeScript's type system.
  • No shell string interpolation: Never use execSync(\cmd ${userInput}`)or interpolate environment variables / config values intoexecSync/spawnSyncstrings. Shell metacharacters cause **command injection (OWASP A03)**. UseexecFileSync('git', ['arg1', arg2])` with a static command + separate args array instead.
  • No unvalidated SSRF origins: When a URL comes from env vars or config (e.g., FEEDBACK_API_URL), validate it against an allowed-origin allowlist before calling fetch() / axios.
  • No Plaintext: Never commit secrets.
  • No Trust: Validate everything server-side.

References

See references/REFERENCE.md for Zod validation, secure cookie setup, JWT auth, security headers, and RBAC patterns.

Canonical response anchors

When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:

  • HttpOnly

© HoangNguyen0403, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/typescript/typescript-security of HoangNguyen0403/agent-skills-standard.

  • SKILL.md
  • evals/evals.json
  • references/REFERENCE.md

Open the folder on GitHubat commit b529c2d

Compare with similar skills

Typescript Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Typescript Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Typescript Security this skillHoangNguyen0403/agent-skills-standard572—~817Automated safety check: NotesMIT
Typescript Patternssoftspark/ai-toolkit179—~1.6kAutomated safety check: PassApache-2.0
Add Server Env Var for User Settinglobehub/lobehub83k—~644Automated safety check: PassCustom licence
Livewire Developmentcoollabsio/coolify63k—~964Automated safety check: PassMIT
Ultraciteagustinusnathaniel/nextarter-tailwind1252 repos~1.2kAutomated safety check: PassMIT
Livewire Developmentyungifez/skuul4091 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Typescript Patterns

    softspark/ai-toolkit

    TypeScript types: generics, discriminated unions, Zod, satisfies, branded types.

    179 GitHub stars~1.6k tokensUpdated 2 days ago
    Frontend & DesignAuto-check passed
  • Adds a server-side environment variable that sets the default for a user setting in LobeHub, wired from the env schema through server config to the user store and docs.

    83k GitHub stars~644 tokensUpdated today
    DevelopmentAuto-check passed
  • Livewire Development

    coollabsio/coolify

    A skill your agent uses for any task or question involving Livewire.

    63k GitHub stars~964 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Ultracite

    agustinusnathaniel/nextarter-tailwind

    Ultracite is a zero-config linting and formatting preset for JavaScript/TypeScript projects.

    125 GitHub starsUsed in 2 repos~1.2k tokens
    DevelopmentAuto-check passed
  • Livewire Development

    yungifez/skuul

    A skill your agent uses for any task or question involving Livewire.

    409 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Code Review

    nteract/semiotic

    Review Semiotic pull requests for behavioral bugs, regressions, contract drift, and missing evidence.

    2.7k GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed

More from HoangNguyen0403/agent-skills-standard

All 211 skills in this repo
  • Subagent-Driven Development

    HoangNguyen0403/agent-skills-standard

    Runs a multi-task implementation plan by sending each task to a fresh implementer subagent, reviewing it independently, then reviewing the whole branch.

    572 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • draw.io Architecture Diagramming

    HoangNguyen0403/agent-skills-standard

    Draws architecture diagrams as editable draw.io files from a JSON spec, with a fixed house style, one C4 level per diagram and evidence-tagged shapes.

    572 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Android Navigation 3 Guide

    HoangNguyen0403/agent-skills-standard

    Implements and migrates to Jetpack Navigation 3 in Compose: NavDisplay, typed route objects, a state-list back stack, deep links, multiple back stacks and dialog scenes.

    572 GitHub stars~687 tokensUpdated yesterday
    Auto-check passed
  • Angular HttpClient Standards

    HoangNguyen0403/agent-skills-standard

    Sets rules for Angular HTTP code: functional interceptors, typed requests, services that own every call, and httpResource for reactive data loading in Angular 17+.

    572 GitHub stars~652 tokensUpdated yesterday
    Auto-check passed
  • Angular Tooling

    HoangNguyen0403/agent-skills-standard

    Angular CLI usage, code generation, build configuration, and bundle optimization.

    572 GitHub stars~743 tokensUpdated yesterday
    Auto-check passed
  • Common Code Review

    HoangNguyen0403/agent-skills-standard

    Conduct high-quality, persona-driven code reviews. An agent skill from HoangNguyen0403/agent-skills-standard.

    572 GitHub stars~772 tokensUpdated yesterday
    Auto-check passed

Questions about Typescript Security

What does Typescript Security do?

Secure server-side TypeScript input, auth tokens, and injection boundaries. Typescript Security is an agent skill from HoangNguyen0403/agent-skills-standard. Secure server-side TypeScript input, auth tokens, and injection boundaries.

When should I use Typescript Security?

Typescript Security fits situations like: API/request validation; sensitive configuration; defer client-only React form validation and generic linting.

How do I install Typescript Security in Claude Code?

Run `npx skills add HoangNguyen0403/agent-skills-standard --skill typescript-security -a claude-code`. Or copy the skill folder (skills/typescript/typescript-security in HoangNguyen0403/agent-skills-standard) into .claude/skills/typescript-security in your project. Claude Code loads it when a task matches its description.

How do I install Typescript Security in Codex?

Run `npx skills add HoangNguyen0403/agent-skills-standard --skill typescript-security -a codex`. Or copy the skill folder (skills/typescript/typescript-security in HoangNguyen0403/agent-skills-standard) into .agents/skills/typescript-security in your project. Codex loads it when a task matches its description.

Can I use Typescript Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add HoangNguyen0403/agent-skills-standard --skill typescript-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/typescript-security, .gemini/skills/typescript-security, .github/skills/typescript-security and .opencode/skills/typescript-security in your project.

What does Typescript Security need to run?

Going by SKILL.md and its folder, Typescript Security needs credentials named JWT_SECRET. Our summary lists: Node.js; A credential in JWT_SECRET.

Does Typescript Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Typescript Security safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Typescript Security use?

Typescript Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Typescript Security use?

About 817 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 910 tokens, read only when the agent opens those files.

What are the alternatives to Typescript Security?

Skills that share tags, products or a category with Typescript Security: Typescript Patterns (softspark/ai-toolkit, 179 stars), Add Server Env Var for User Setting (lobehub/lobehub, 83k stars), Livewire Development (coollabsio/coolify, 63k stars) and Ultracite (agustinusnathaniel/nextarter-tailwind, 125 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Typescript Security?

HoangNguyen0403 (a GitHub user) maintains it in HoangNguyen0403/agent-skills-standard, which has 572 GitHub stars. The repository holds 211 skills in this directory. The repository was last updated on October 9, 2026.

Source: HoangNguyen0403/agent-skills-standard on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.