Back to Skills

typescript-security-review

Provides security review capability for TypeScript/Node.js applications, validates code against XSS, injection, CSRF, JWT/OAuth2 flaws, dependency CVEs, and secrets exposure. Use when performing security audits, before deployment, reviewing authentication/authorization implementations, or ensuring OWASP compliance for Express, NestJS, and Next.js. Triggers on "security review", "check for security issues", "TypeScript security audit".

315stars37forksUpdated 8/1/2026

Security Assessment

Safe(95/100)
Security Score95/100

About typescript-security-review

This is a defensive security-review skill for TypeScript and Node.js codebases. It solves the problem of running a consistent, OWASP-aligned audit over an application before deployment: instead of ad hoc checks, it walks a structured review covering authentication and authorization, injection, input validation, XSS, secrets management, dependency risk, and security headers. Findings are classified by severity (Critical, High, Medium, Low) with remediation examples, and the skill can delegate deeper analysis to a dedicated security-expert agent.

The workflow is a numbered checklist with verification checkpoints at each stage. It uses grep and read to locate security-sensitive patterns, confirms that route handlers enforce auth guards, checks database queries for parameterization, verifies input validation with Zod/Joi/class-validator, inspects React components for unsanitized dangerouslySetInnerHTML, scans for hardcoded secrets and gitignored env files, runs npm audit for dependency CVEs, and reviews helmet/CORS/rate-limiting/cookie-flag configuration. Reference files expand on XSS prevention, dependency and supply-chain security (typosquatting, install-script attacks, dependency confusion), security headers, input validation, common vulnerabilities, and OWASP guidance for Express, NestJS, and Next.js.

It targets application security engineers and TypeScript developers preparing for production releases, code reviews of auth flows, or compliance checks (GDPR, HIPAA, SOC2 data handling). The guidance is entirely protective in intent: it teaches how to find and fix weaknesses, recommends secure patterns like DOMPurify sanitization and startup env-var validation, and explicitly steers toward least-privilege credential handling. No offensive tooling or exploit automation is present.

FAQ

What does this skill actually do?

It runs a structured, severity-classified security audit of a TypeScript/Node.js codebase against the OWASP Top 10 and framework-specific patterns, producing findings with remediation guidance.

Which frameworks does it cover?

Express, NestJS, and Next.js, including framework-specific concerns like Next.js NEXT_PUBLIC_ variable exposure and React dangerouslySetInnerHTML.

Does it modify my code automatically?

Its primary role is review and reporting. It reads and greps for issues and produces a report with remediation examples; the allowed tools include Edit, but the documented workflow centers on analysis rather than autonomous rewrites.

What dependency-security checks are included?

It runs npm audit, recommends committing lock files and using npm ci, and covers supply-chain risks such as typosquatting, malicious install scripts, and dependency confusion, plus tools like Snyk and Socket.dev.

Is this an offensive or defensive tool?

Purely defensive. It identifies vulnerabilities and prescribes fixes and secure configuration; it does not generate exploits or attack automation.

All Files

7 files
references/dependency-security.md6.2 KB
View
references/xss-prevention.md1.2 KB
View
references/common-vulnerabilities.md7.0 KB
View
references/security-headers.md1.5 KB
View
references/input-validation.md1.9 KB
View
SKILL.md9.3 KB
View
references/owasp-typescript.md6.7 KB
View

Install typescript-security-review

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill