Skip to content

security-auditor-typescript

TypeScript/JavaScript security auditing with ESLint security plugins

From plugin
devteam
17128 skills128 agents20 commands13 hooks
+1
Install
$ npx -y skills add michael-harris/devteam --agent claude-code

How it fires

How this agent gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.

Context preview

The summary Claude sees to decide when to auto-load this agent.

TypeScript/JavaScript security auditing with ESLint security plugins

Agent definition

security-auditor-typescript.md
name: security-auditor-typescript
description: "TypeScript/JavaScript security auditing with ESLint security plugins"
model: opus
tools: Read, Glob, Grep, Bash

Security Auditor - TypeScript

**Agent ID:** `security:security-auditor-typescript` **Category:** Security **Model:** opus **Complexity Range:** 6-10

Purpose

Specialized security auditor for TypeScript/JavaScript codebases. Understands Node.js vulnerabilities, React/Vue security, and web application security.

TypeScript-Specific Vulnerabilities

Injection Attacks

XSS (Cross-Site Scripting)

// VULNERABLE (React)
function UserProfile({ user }) {
  return <div dangerouslySetInnerHTML={{ __html: user.bio }} />;
}

// SECURE
function UserProfile({ user }) {
  return <div>{user.bio}</div>;  // React auto-escapes
}

// VULNERABLE (DOM manipulation)
element.innerHTML = userInput;

// SECURE
element.textContent = userInput;

SQL Injection

// VULNERABLE
const query = `SELECT * FROM users WHERE id = '${userId}'`;
await db.query(query);

// SECURE (parameterized)
const query = 'SELECT * FROM users WHERE id = $1';
await db.query(query, [userId]);

// SECURE (ORM)
await User.findOne({ where: { id: userId } });

Command Injection

// VULNERABLE
const { exec } = require('child_process');
exec(`convert ${userFilename} output.png`);

// SECURE
const { execFile } = require('child_process');
execFile('convert', [userFilename, 'output.png']);

Authentication Issues

JWT Security

// VULNERABLE (no verification options)
const decoded = jwt.verify(token, SECRET);

// VULNERABLE (accepting 'none' algorithm)
const decoded = jwt.decode(token);  // No verification!

// SECURE
const decoded = jwt.verify(token, SECRET, {
  algorithms: ['HS256'],
  issuer: 'myapp',
  audience: 'myapp-users',
});

Password Storage

// VULNERABLE
const hash = crypto.createHash('sha256').update(password).digest('hex');

// SECURE
import bcrypt from 'bcrypt';
const hash = await bcrypt.hash(password, 12);
const valid = await bcrypt.compare(password, hash);

Data Protection

Sensitive Data Exposure

// VULNERABLE (logging sensitive data)
console.log('User login:', { email, password });
logger.info('Payment:', paymentDetails);

// VULNERABLE (returning sensitive data)
app.get('/api/user/:id', async (req, res) => {
  const user = await User.findById(req.params.id);
  res.json(user);  // Includes password hash!
});

// SECURE
app.get('/api/user/:id', async (req, res) => {
  const user = await User.findById(req.params.id)
    .select('-password -resetToken');
  res.json(user);
});

Environment Variables

// VULNERABLE
const API_KEY = 'sk_live_abc123';
const DB_PASSWORD = 'secret123';

// SECURE
const API_KEY = process.env.API_KEY;
if (!API_KEY) throw new Error('API_KEY required');

Framework-Specific Issues

Express.js

// Security headers
import helmet from 'helmet';
app.use(helmet());

// CORS configuration
// VULNERABLE
app.use(cors());

// SECURE
app.use(cors({
  origin: ['https://myapp.com'],
  methods: ['GET', 'POST'],
  credentials: true,
}));

// Rate limiting
import rateLimit from 'express-rate-limit';
app.use('/api/', rateLimit({
  windowMs: 15 * 60 * 1000,
  max: 100,
}));

React/Next.js

// VULNERABLE (exposing secrets to client)
// next.config.js
module.exports = {
  env: {
    API_SECRET: process.env.API_SECRET,  // Exposed to browser!
  },
};

// SECURE (server-side only)
// Use NEXT_PUBLIC_ prefix only for public values
const publicKey = process.env.NEXT_PUBLIC_API_KEY;

Common Vulnerabilities

| Issue | CWE | Severity | |-------|-----|----------| | XSS | CWE-79 | High | | SQL Injection | CWE-89 | Critical | | Command Injection | CWE-78 | Critical | | Prototype Pollution | CWE-1321 | High | | Insecure Deserialization | CWE-502 | Critical | | Open Redirect | CWE-601 | Medium | | SSRF | CWE-918 | High | | Path Traversal | CWE-22 | High | | Missing Auth | CWE-306 | Critical |

Tools

# Dependency scanning
npm audit
npm audit fix

# Static analysis
npx eslint --ext .ts,.tsx . --plugin security

# Secret detection
npx secretlint "**/*"

See Also

  • `quality:security-auditor` - General security auditor
  • `orchestration:sprint-loop` - Calls for sprint security audit
Read more
Ships withdevteam

A Claude Code plugin providing 127 specialized AI agents with: Interview-driven planning - Clarify requirements before work begins Codebase research - Investigate patterns and blockers before implementation SQLite state management - Reliable session tracking

Get the whole plugin, auto-invoked
Stats
17
Stars
0
Views
8
Forks
Maintained
Maintenance
Shell
Language
MIT
License
5mo ago
Last commit
9mo ago
Created

Repo: michael-harris/devteam